= INSTITUTE OF 
e 0 i e. INTERNATIONAL 
FINANCE 


The effectiveness of financial crime risk management 
reform and next steps on a global basis 


The Institute of International Finance and Deloitte White Paper 
November 2021 


Contents 


Executive summary 
Introduction 


Part 1: The global outlook on financial 


crime risk management reform 


Part 2: A way forward on continuing to enhance 
effectiveness in financial crime risk management 
- 1 The use of financial intelligence 
- 2 Risk prioritization 
- 3 Technology and innovation 


- 4 International cooperation and capacity building 
Contacts 


Endnotes 


03 


04 


PAS 


30 


The effectiveness of financial crime risk management reform and next steps on a global basis 


Executive summary 


Policymakers, law enforcement, regulators and the private sector 
have all taken important steps to protect the citizens that they 
serve and the economies in which they operate through significant 
investment in people, processes, and technology. Despite this, it has 
continued to be difficult to effectively stem the flow of illicit finance. 


In this paper, the Institute of International Finance (IIF) and Deloitte 
Transactions and Business Analytics LLP (“Deloitte”) highlight four 
areas of focus where continued reform could build on the good 
work and progress already underway globally to help improve 

the effectiveness of the anti-financial crime framework: 1. the use 
of financial intelligence; 2. risk prioritization; 3. technology and 
innovation; and 4. international cooperation and capacity building. 


This paper also highlights important instances of ongoing systemic 
improvements, how similar efforts can be deployed across 
jurisdictions, and how policymakers could prioritize international 
cooperation and coherence. Strong global leadership is vital, 

as is a continued commitment from all stakeholders to take 

an empowered, proactive, collaborative and outcome-focused 
approach to tackling financial crime. Only by working collectively 
as a coordinated international system can public and private 
stakeholders truly address, and ultimately prevent, domestic and 
cross-border financial criminality. 


03 


The threat posed by crimin 


alin 


The effectiveness of financial crime risk management reform and next steps on a global basis 


cursion into the international 


financial system is a global problem requiring a coordinated, wide- 


reaching response and a clear 
framework for fighting financia 
to be done at all levels to help i 


public pol 


icy focus. An effective 
crime is essential and more needs 


dentify and stem the flow of illicit 


finance which supports malignant activities such as terrorism, 


sexual exploitation, human 


crime, drug smuggling, and cybercrime. 
integrity of 
th increasingly complex and international 


between the 
system 


connection 


the financial -wi 


tra 


ficking, fraud, environmental 
There is also an inherent 
finance and the stability of 


criminal activity being a factor that significantly undermines cross- 


border financial strength. ' 


In 2019, the IIF and Deloitte UK laid a way forward on mitigating 


illicit 


flows through a combination of internationally consistent 


regulatory reform and an intelligence-led approach to financial 
crime risk management.? The 2019 paper identified seven key 


enab 


ers to amore effective system through a process which 


canvassed financial institutions (FIs), policymakers, regulators and 
law enforcement across Europe, Africa, the Americas, Asia, and 


the 


iddle East. Those enablers included a focus on information 


exchange, public/private cooperation, and systemic reform with an 
emphasis on achieving better outcomes. 


to gauge current 
ndustry and the 
challenge facing the 
the IIF and Deloit 
of stakeholders at F 


Since then, noteworthy progress has been made around the world 
across those issues, building on 
by the Financial Action Task Force 
of the public and private sectors to 
crime is identified, mitigated, and ul 
perspectives from 
public sector on that progress and the continued 
global financial 
te US have combined 
s and public au 
oney Laundering and Countering t 


years of good work spearheaded 
FATF) and the collective efforts 
improve the way financial 
timately prevented. In order 
within the financial services 


crime risk management regime, 
research with interviews 
thorities responsible for Anti- 
Financing of Terrorism 


(AML/CFT) and the wider financial crime policy and enforcement 
environment across both developed and emerging markets. 


The result of that research 
aims to present a global ou 
crime ris 
view on how to continue to 
the framework for mitigatin 
system. With the impact o 
challenges in relation 


process is d 


tloo 


enh 
gth 


fthe 
o financial crime activity,? wi 


istilled in this paper and 
on the current state of financial 


management and compliance, as well as an updated 


ance the overall effectiveness of 
e criminal misuse of the financial 
COVID-19 pandemic raising novel 
th new risks 


emerging (including, notab 
pub 


y, th 


icly funded climate finance initiatives and con 


e potential for criminal abuse of 
tinued public 


sector investment in pandemic recovery programs), and with 
numerous financial crime compliance reform efforts across the 


globe, there is fresh opportunity to explore how to address factors 
that prevent the optimum means of tackling systemic financial 


cri 


me issues by leveraging sound practices, and 


international coordination. 


addressing gaps in 


There are a number of the potential approaches laid out in this 


stakeho 
sti 


implementa 
jurisdictions. 


As such, Part 1 of this paper lays out examples o 


paper that are already being considered and/or developed by 
ders, albeit at varying levels of maturity, 
ll to be considered. Thi 


and some are 


S paper could also, therefore, assist in 
encouraging firms, regulators, policymakers, and 
agencies to accelerate th 


law enforcement 


ese reforms within their respective 
tion programs and to work to align e 


fforts across 


f noteworthy 


reform efforts at the international, regional, and domestic levels. 


Part 
the 
eh 
2. Ri 


3. Technology and innovation 


4, Internationa 


Thi 


‘iri 


financial cri 


S paper high 


fthe 


ationa 


cooperation and capacity building 


lights important instances of sys 
improvements that are ongoing, how similar efforts can be 
deployed across juri 
prioritize intern 
is recognized that the 


sdictions and how policyma 
cooperation and coheren 
financial crime framework 


2 provides considerations on how to make further progress in 
following key areas, considering these reform efforts: 

he use of financial intelligence 
sk prioritization 


temic 


ers can better 
ce. While it 


s in different 


sdictions are at different levels of maturity, th 
homogeneity o 


e globa 


drivers, effects and solutions concerning 

me warrant a sustained, collective focus by the world 
community to continue to deliver outcomes which 
isuse of finance and 
inancial stability. 


stop the criminal 


its subsequent damage to society and 


There is an urgent need for efforts in this policy area. Though 
reform processes m 


appropriate amount 


are assuaged, 
moves at a 


the cr 


rate whic 


initiatives. As has be 


was key to add 


behavior. Li 


the opportuni 
significant ri 


expeditious and dyn 
crime architecture to mitigate threats in a more efficient manner. 


ust be carefully considered and should take an 
of time to ensure any negative consequences 
iminal element in international finance 

h can outpace many well-intentioned policy 
en seen during the COVID-19 crisis, speed 
ressing changing methods and 
ewise, technological developmen 
policymakers do not 
ties an 


modes of criminal 
ts move quickly. If 
have a full picture of new developments and 
d the threats they may create, then there is 
sk that policy reform will fall short 
effective. There needs to be a continued focus on delivering 
amic improvements to the global anti-financial 


or only be briefly 


05 


pope bel Bad Pa 
Pe 
° eg eer peg el bl bl 
* Pd eR id al dd 
° Rr Pea a! 
eel ep 


‘Bd rpy 4 

. fin 
Prins Whip 

eavea ts hip 


— srantante 


PPR rag 


The effectiveness of financial crime risk management reform and next steps on a global basis 


Part 1: The global outlook 
on financial crime risk 
management reform 


The focus on efforts to improve AML/CFT and the broader financial 


crime ecosystem have been at the forefront of policymaking for 
decades. The FATF was established as an inter-governmental 


organization 
body in setting globa 


for combating money laundering a 
such as MONEYVAL, the Asia-Pacifi 
(APG) and the Eurasian 
and application of the FATF Recom 
have combined with the work of th 
domestic rules and ensure interna 


Units (FIUs) 
through such fora as Interpol and 


rime risk management frammewor 


On EF a S 


from the collective 
to be guided by fundamenta 


standards an 


Group suppor 


implemented. International collaborat 
through the Egmont Group and law enforcement work 

Europol actively engage in efforts 
which target emerging risks across the globe5 


cG 


tion 


over thirty years ago and has been the leading 

d promoting effective 
implementation of legal, regulatory, and operational measures 
nd terrorist financing. Bodies 


roup on Money Laundering 


t multilateral 
mendations.’ National efforts 
e€ private sector 


al standards 


on of Financi 


s through upda 


cooperation 


to strengthen 
are effectively 
al Intelligence 


n addition to this sustained, long-term focus, it is important to 
ote that a number of additional efforts are currently underway 
t the global, regional, and national levels to modernize financial 


tes to domestic 


nd multilateral regimes. The drivers of such efforts often come 
understanding that effective ou 
reform through enab 


tcomes need 
ers of a better 


system. These enablers continue to include, among others, 
enhanced information exchange, public/private cooperation, 
the use of technology, and the coherent implemen 


international standards. 


e) 


tation of 


While Part 2 of this paper looks at a way forward to enhancing 
effectiveness in financial crime risk management through such 
enablers, the following examples of recent reforms (and/or 
reforms that are underway), highlight the collective importance 

f addressing both the fundamental building blocks of risk 
management and the need to find innovative solutions for tackling 


financial crime. The opportunities presented herein to coordinate 


reform efforts and address sound 


practices across jurisdictions 


- and through international bodies — are referenced across this 
paper and should be a priority to potentially avoid fragmented 


approaches to these issues, which 
terrorist financiers. 


can be exploited by criminal and 


1. International standard setting bodies: 


At the global level, the internati 


onal standard-setting bodies 


(e.g., the Basel Committee on Banking Supervision, the 
Committee on Payments and Market Infrastructures (CPMI), 
and the FATF continue to set requirements and provide 


guidance to help drive internat 
worldwide anti-financial crime 


During the two-year German p 
has prioritized countering mon 
smuggling, environmental crim 


ional consistency in the 
framework. 


residency of the FATF, the body 
ey laundering and migrant 
e, illicit arms trafficking and the 


financing of ethnically- or racia 


broadly, the FATF has set important targets around digital 
transformation of AML/CFT - includi 


privacy and data pooling - add 
transparency, tackling 


standards, and continuing to follow 
things, recommendations and guidance around prolifera 
asset service providers (VASP) and 


of financing risk, virtua 


ly-motivated terrorism.° More 


ng issues around data 
ressing beneficial ownership 


unintended consequences from the FATF 


through on, among other 
tion 


the application of risk-based supervision. Work on enhancing 
the effectiveness of implementation of FATF measures 


continues, and a FATF Global N 


etwork assessment process iS 


ongoing, which presents valuable opportunities for improving 
international coherence in standards. FATF has also increased 


its 


focus on ensuring the effectiveness of AML/CFT regimes. 


The Financial Stability Board (FSB), CPMI and the Basel 


Committee, as well as the FATF, 


, are working on an ambitious 


07 


The effectiveness of financial crime risk management reform and next steps on a global basis 


08 


roadmap at the behest of the G20 to enable “faster, cheaper, 
more transparent, and more inclusive cross-border payment 
services.”’ As part of the building blocks on how payment system 
enhancements could be achieved, these bodies are considering 


issues for applying AM 


L/CFT rules consistently internationa 


ly, 


fostering Know-Your-Customer (KYC) and identity information- 


sharing and, in conjunction with AML/CFT requirements, 
reviewing the interaction between data frameworks and 
protection. This effort holds promise in not on 
cross-border payment 
to de-risking and positi 
issues which prevent a 


framework. 


The Basel Committee has also amen 
management of risks related to mon 


s but also in addressing structural dri 
vely impacting many of the anci 
fully effective global anti-financia 


data 
ly enhancing 
vers 
lary 


cri 


me 


ded its guide Sound 
ey laundering and financing 


of terrorism, enabling greater interaction, cooperation, and 


information exchange between 
supervisory authorities.® This g 
assist in filling gaps in this area, 
facilitate such cooperation in the 


context. 


United States: In the United Sta 
consensus among regulators, legi 
industry that compliance with A 
the amendments passed after 


ie) 


A 


inc 


bally 
udi 


tes (US), there is a growing 
slators, law enforcement, and 
L/CFT req 
the Bank Secrecy Act (BSA), 


L/CFT and prudential 


consistent guidance can 
ng the mechanisms which 


jurisdictional and international 


uirements, including 


has evolved into a layered and inefficient system that does not 


serve the need 


resulted in regu 
do little to mitigate the risks associated wi 
6, 2020, the Financial Cri 
Network (FinCEN) signaled the s 
fundamentally reform the AML/CFT regime 
Rulemaki 
Effectiveness.? The ANPRM introduced a proposed 
L program effectiveness, 
AML Priorities, and a possible regulatory requirement for ris 


On September 


an Advance No 
Program 


definition of AM 


assessments. 


On January 1, 2021, the AML Act of 2020 (USA 


and reinforced 


s of law enforcem 
ated Fls spendi 


tice of Proposed 


and codified a ris 


ent. In many instances, this has 
ng time on activities that may 


th financial crime. 
mes Enforcement 


tart of a multi-year effort to 


in the US through 
ng (ANPRM) on AML 


the concept of Strategic 


LA) became 


-based approach for AML/ 


CFT programs. For instance, the US AMLA required FinCEN 


to estab 


As required by 
the first govern 
publication of t 


CFT programs 


the primary focus of US reg 
from maintaining 


ish national AML/CFT pr 


the US AMLA, on J 
ment-wide nation 
he priorities is a si 


alA 


gnificant step 
ulators and Fls concerning AML/ 
techn 


iorities for Fls to incorporate 
them into their AML/CFT programs, and for regulators and 
examiners to incorporate into rules, guidance, and examinations. 


une 30, 2021, 


FInCEN issued 
L/CFT Priorities. The 
forward in shifting 


ical compliance to a more 


risk-based, innovative, and outcomes-oriented approach to help 
combat financial crime and safeguard national security in the 


evolving financial environment. 


European Union: The European Union 
several initiatives aimed at tackling illicit 
European Commission's (EC) 2020 AML Acti 


six areas 


financial 


maturity 
member 


between 


mature finan 
S paper. 


thi 


enforcemen 


standardiza 
cooperation 
the EC issued a legisla 


priorities set 
on public pri 


a 
m 

the European Public Prosecu 
tackling comp 

m 


and supervisi 


may impact 


EU 
fina 


of focus including the creation of a 


tion of AM 


crime across 


ex 


on is understan 


vate partnerships (PPPs 
the bloc." 


L supervision through 
EU level supervisory body, the developm 
and enhanced coordination 
tive proposal takin 
out in the Action Plan wi 


be 


) has launched 
ncial flows. The 


on Plan set out 


single rule book, 
the creation of an 


ent of public/private 


tween FIUs.'° In 2021, 


g forward many of the 
th a separate consultation 


and th 


eir role in combatting 


addition to its efforts to enhance the financial crime risk 
anagement framework at the policy level, the EU has created 
tor’s Office, which is charged with 
financial crimes against the EU budget in a 
ore coordinated manner. The EU focus on standardization 
dable given the differing levels of 


in financial crime frameworks and approaches across 


states. It remains to 


the developmen 
the 


be seen how policy changes 

t of collaborative ways of working 
public and private sectors that is a feature of more 
cial crime frameworks, which is discussed further in 


. Singapore: Financial crime risk management, compliance and 
t continues to remain a top priority for Singapore. 


The Monetary Authority of Singapore (MAS) persists with its 
supervisory efforts around robust execution of financial crime 


and advanced data analytics. 


The Singapore government is one of the global 
cryptocurrency regulations to mitigate the mon 
terrorism financing risks associated with 
passed the Payment Services Act (PS Act) in Jan 
requires entities that deal in and/or facil 
digital payment tokens (DPT 


risk management in Fls and in encouraging the 


Such providers of DPT services are required 
AML/CFT requirements which incl 


assessments, perform Cus 
itor and report suspicious 
in Par 
the scope of regulated D 
fer of 


and mon 
to the PS 
enhance 
custodia 


Act were passed"? 


services and trans 


In keepin 


g with the theme of 


transacti 


ons, the MAS pub 


regu 


ished in J 


ia 
a 


ude th 
tomer Due Di 


transact 


use of technology 


eaders in passing 
ey laundering and 


these assets. The MAS 


uary 2020, which 


itate the exchange of 
T) to hold a payment services 


icence. 
to comply with 


e need to conduct risk 
ligence (CDD) measures 


ions. Amendments 


ment in January 2021 to 
| services, and include 
DPTs. 


ating cross-border 
une 2021 a consultation 


paper’? on AML/CFT requirements applicable to cross-border 


business 


arrangements between ca 
and their foreign related corporatio 


pital ma 


ns (FRC), 


rkets intermediaries 
their foreign head 


offices, or foreign branches, under Singapore's Securities and 


Futures Act (SFA) and Finan 


cial Advisers Act (FAA). Singapore 


Fls will be provided a transition period of six months to comply 


The effectiveness of financial crime risk management reform and next steps on a global basis 


with the requirement to have policies and procedures in place to 
oversee the conduct of FRC or foreign offices. These include (i) 
record-keeping - CDD and Transaction Monitoring information 
must be kept for at least five years; (ii) internal policies are to be 
updated relating to CDD and Transaction Monitoring; and (iii) 
provision of CDD/Transaction Monitoring Records upon request. 


n October 2021, the MAS announced that it will implement a 
digital platform and an enabling regulatory framework for Fls to 
share with one another relevant information on customers and 
transactions to prevent ML, TF, and proliferation finance (PF). The 
new digital platform, named COSMIC, for “Collaborative Sharing 
of ML/TF Information & Cases”, will enable Fls to securely share 
information on customers or transactions where they cross 
material risk thresholds. It aims to support Fls to identify and 
disrupt illicit networks and enhance SARs. The information is 
shared in a structured data format and is designed to integrate 
with data analytics tools to help Fils collaborate productively and 
at scale. The sharing creates an enriched data pool of higher 

risk activities and customers that Fls can use to dynamically 
assess Customer risks and that MAS will use in risk surveillance 
to detect illicit networks to target for supervisory interventions. 
In its consultation paper,'* MAS explained that it will require 
participant Fls to implement robust measures to safeguard 
against unauthorized use and disclosure of COSMIC information. 


United Kingdom: The United Kingdom (UK) has continued to 
drive enhancements to its financial crime framework through 
the delivery of the Economic Crime Plan. Significant investments 
are slated, to build FIU capacity and capability, and to bolster 
the capabilities of the national fraud reporting service, however 
these investments come against a backdrop of significant 
increases in SAR volumes and reported frauds. 


Her Majesty’s Treasury (HM Treasury) is undertaking two financial 
crime-related consultations. The first is to make time-sensitive 
changes to regulations to enhance clarity in certain areas and 
ensure compliance with international standards. The second 
is amuch broader consultation, seeking stakeholder views on 
the overall effectiveness of the AML regime, including on the 
potential value of new concepts such as the introduction of 
national priorities similar to those set out in the US AMLA, while 
also assessing whether key elements are operating as intended 


The Home Office is also expected to consult on potential changes 
to AML and information sharing legislation in 2021. Between 

both consultations, there are significant opportunities for 
stakeholders to work collectively to drive effective financial crime 
reforms in the UK. 


6. Other global examples: Though 
some specific international and jur 


this paper highlights above 
isdictional examples that 


encompass major structural change in AML/CFT rules and 


supervision, there have been deve 


opments across other 


countries and regions which merit significant attention, and 


which could be replicated in other 
closely across global reform efforts. 


In Australia, the Australian Fintel Al 


places or connected more 


iance continues to bring 


together increasing numbers of banks, remittance service 
providers, and gambling operators, as well as law enforcement 
and security agencies, to share intelligence and develop solutions 
on preventing and disrupting financial crime. Investments have 
also been allocated to enhancing reporting systems for Fls to 
streamline compliance and drive more timely and effective 
financial intelligence. A parliamentary committee is examining the 
adequacy and efficacy of the national AML/CFT regime and will 


report later this year. 


ore broadly in the Middle East, North Africa, and Sub-Saharan 
Africa, there is a continued focus on technical assistance and 
training through organizations such as Middle East and North 
Africa Financial Action Task Force (MENAFATF) and on building 
information sharing capabilities. These include efforts such as 
the MANSA CDD platform in Africa, which has been established 
by a partnership of private sector and central banks to provide 
a single source of primary data required to conduct CDD on 
African entities in order to alter risk perceptions, address de- 
risking on the continent, and promote trade in Africa. PPPs 

are being established or are operating in multiple jurisdictions 
including, for example, in Hong Kong (the Fraud and Money 


Laundering Intelligence Taskforce), South Africa (the Anti-Money 
Laundering Integrated Taskforce), and Canada (Project Protect). 


Several jurisdictions within Europe are also innovating to 
enhance their response to financial crime beyond the EU- 


focused reform initiatives no 
five banks and Finanspolisen 
FIU - formed the Swedish An 
Task Force (SAMLIT), which is 


operational information, with 
banks in that effort. 


ted herein. For instance, in Sweden, 
Rikskriminalpolisen — the Swedish 
ti- Money Laundering Intelligence 

a co-operation for the sharing of 
work ongoing to include more 


Other examples include the development of information sharing 
utility models such as ‘Transaction Monitoring Netherlands’ '® 
and Invidem in the Nordics'’. The Nordic and Baltic countries 
have also formed the Nordic Baltic AML/CFT Working Group, 
which is designed to allow authorities to exchange experiences 
and information on financial crime matters across countries and 
agree on measures to increase cooperation.”? 


09 


The effectiveness of financial crime risk management reform and next steps on a global basis 


Part 2: A way forward on 
continuing to enhance 
effectiveness in financial crime 


risk management 


As recognized in Part 1 of this paper, a critical opportunity exists now to make meaningful changes in how th 
addresses illicit finance and to build upon the advancements of the past several decades. Momentum for reform is being driven by the 

collective need to mitigate and prevent financial crime consistently across borders and across industries and sectors. Building on the work 
that has already been undertaken and efforts which are currently underway, the following areas warrant fur 


through public and private sector cooperation and coordination: 


1. The use of financial intelligence 


The management of financial crime can be improved by 
facilitating the increased sharing of information, and by more 
effectively using financial activity, threat and risk data linked to 
crime and terrorism, both domestically and internationally.*! 
evertheless, issues such as inconsistent legal frameworks for 
data protection, the management of SAR type information, 
privacy and bank secrecy continue to present barriers that 
inhibit an effective intelligence-led approach to risk 
management. Building on the enablers identified in the 2019 
white paper, several key issues remain vital in developing a 
better anti-financial crime system and should be considered 
across reform efforts. 


a. Suspicious activity and transaction reporting 
Background 


The Suspicious Transaction Report (STR)/Suspicious Activity 
Report (SAR) regime is a cornerstone of the global financial 
crime risk management framework. However, there are a 
number of acknowledged challenges to its effective application. 
Legal frameworks penalize the “failure to report”, but do not 
generally sanction overreporting. This encourages reporting 


insti 


tutions to adopt a defensive reporting post 


e global financial community 


ther discussion and development 


ure, which 


— juxtaposed with a low threshold for “suspicion”, and an 


all-c 


rimes approach - drives u 


p SAR volumes wi 


commensurate gains in repor 
outcomes - for example, increased prosecution 


seiz 


tran 


sec 


High vol 


jurisdicti 


ures. 


sign 


thout delivering 


ting quality or improved 


s or asset 


umes of low-value reporting (whether that be specific 
sactional data and/or suspicious activity, depending on the 
on), consumes resources in both the public and private 
tors in terms of production and review. Often such 
resources could be more effectively deployed elsewhere to 
focus on higher-value activities. It also creates risks that a 
ificant number of innocent parties are reported to, and 
recorded in, government databases in a manner that sits 
uncomfortably with the concepts of proportionality and 


necessity enshrined in most jurisdictions’ data privacy laws 


These challenges are amp 
sharing, and prioritizatio 
sectors are U 


ified where feedback, information 
n between the public and private 
nderdeveloped and do not support or inform the 


accurate identification of suspicion or the effective application 


of the risk-based approach and can mean reporting institutions 


may not know which SARs 


are of high value to the FIU. They can 


be exacerbated further in jurisdictions where supervisory 


11 


The effectiveness of financial crime risk management reform and next steps on a global basis 


12 


frameworks do not prioritize quality over quantity, and do not 
allow efforts to be dialed up or down against mutually agreed 
threats or priorities - or points of integration of funds such as can 
be set out in “Geographical Targeting Orders”. 


A further challenge is that any incident of serious crime is often 
inherently multi-national in nature and has touchpoints across 
multiple institutions. Against this reality, approaches to data and 
information sharing (including the sharing of SARs) are often 
limited by national and organizational borders that can only be 
bridged through processes and arrangements that operate with 
far less agility than that exhibited and leveraged by crimina 
networks. 


This challenge is thrown into sharp perspective when viewed 
through the lens of a major international FI. It is well recognized 
that such institutions can potentially see a complete network of 
suspicious activity across their global data, but limitations on 
international information sharing often prohibit this global view 
being shared with a single (or group) of national law enforcement 
bodies. 


This challenge persists even where intra-group sharing—which 
has been very usefully encouraged by the proactive stance taken 
on Recommendation 18 by the FATF?? —has been supported by 
guidance at the national level.2? As such, it remains the case that 
group wide sharing is not yet synonymous with group wide filing, 
and so while all the component parts of a comprehensive 
intelligence picture may exist in the system, they are rarely — if 
ever — assembled into a complete understanding, and certainly 
not at pace. 


To overcome these issues, SAR mechanisms should be reformed 
in practical ways to enable them to become more effective. Taken 
together, these reforms have the potential to increase the focus 
and quality of SAR reporting and the overall effectiveness of the 
financial crime framework. Where progress is noted, global 
policymakers are encouraged to take similarly proactive steps to 
work with public and private sector stakeholders to identify 
opportunities to enhance effectiveness in their own jurisdictions. 


Recommendations 


First, it is important that governments and FIlUs continue to 
commit sufficient resources (human and technological), to the 
collective analysis of SARs and STRs, with a specific focus on 
enhancing the speed, volume, and quality of feedback on threats 
and typologies provided to suspicious activity reporters. 
Enhanced and timely feedback should be specific, focused, and 
actionable, for example identifying common payment patterns of 


concern that identified by multiple reporters, to help the 
reporting sector refine the focus of its AML controls, and help the 
system as a whole prevent, detect, and respond to financial 


crime more efficiently 


Second, enhanced SA 
indicators, could form 


cases and 
into a set of national fi 


in the U 
significant beneficia 


The flexibility to enable institutions to dial eff 


assessment process. This SAR analysis sh 
insight derived from in-depth law enforcement analysis of key 


investigations which together could, in time, translate 


and effectively. 


R analysis by FlUs including efficacy 


a key 


input into a national threat 
ould be enriched with 


nancial crime priorities agreed collectively 


between stakeholders; a concept that has now, for example, 

been established in the US through the implementation of the 
US AMLA, and is an idea also being consu 
. The implementation of nationa 
impact on the effect 
regime, if supported by reforms to the supervisory framework 
that could enable reporting efforts to be dia 
focus, and dialed down proportionately in non-priority areas. 


Ited on by HM Treasury 
| prioriti 
iveness of the SAR 


es could have a 


ed up in areas of 


ort up and down to 


reflect priorities as part of an increasingly outcome-focused 


regime is cri 
priority areas there ca 


nnot be a zero-toleran 


tical, as is a recognition that in focusing effort on 


ce approach to 


reporting against low-priority areas. Without such flexibility, the 


introduction of national priorities could crea 


te additional 


reporting burdens, without reducing the high volumes of low 
value reporting that are currently a feature of most SAR regimes. 


The effective impleme 


ntation of national priorities affects a 


broad range of financial crime matters and is discussed more 


widely and in more de 


Third, SAR framework 
reporting entities to th 


exist and limited information an 


the public and private 


FIU. 


ess importance. 


at all clear what inform 


s rely on 
e FIU. Where national 


tail in Section 2. Risk Prioritization. 


information being pushed from 


priorities do not 


d feedback is shared between 
sectors, reporting institutions may not be 
ation is of value to law enforcement or the 


Even where reporting entities do have a good understanding of 
threats and risks, regulatory frameworks and examination 
approaches mandate an all-crimes approach, thereby providing 
ittle latitude for reporters to dial up SAR reporting efforts 
against areas of importance, and to dial down efforts in areas of 


Where specific and targeted national priorities are not in place, 
policymakers could reconsider the balance between “push and 


pull” in the SAR framework. The current, “one size fits a 


” 


approach to reporting might be replaced with a streamlined 


The effectiveness of financial crime risk management reform and next steps on a global basis 


reporting obligation, in which reporters would only be required 
to provide high-level “notifications of suspicion” to the FIU, limited 
to core customer data and a synopsis of the suspicion. Such an 
approach would be entirely consistent with the risk-based 
approach. Over time this process could become increasingly or 
entirely automated (e.g., in SARs relating to structuring or 
unusual deposits or withdrawals, generated primarily due to 
automatic detection of such payments). 


f data within the “notification of suspicion” was of interest to the 
FIU or law enforcement (e.g., hitting a flagged investigation), the 
FIU or law enforcement could request further investigation by 
the reporting entity. The bulk of a reporter's investigative 
capability would be held in reserve to support such proactive 
requests from law enforcement/FIU, ensuring analytical and 
investigative effort within the regulated sector was focused on 
developing intelligence on matters of genuine concern or interest 
to law enforcement. This process would allow national 
frameworks to retain an all-crimes approach, while minimizing 
analytical effort invested in low value reporting. 


Fourth, nations with a commitment to tackling complex financial 
crime should consider how a global Fl's potentially 
comprehensive insight into an instance of international financial 
crime could be shared as a complete SAR analysis in multiple 
jurisdictions, putting a comprehensive picture in the hands of 
investigators. 


Perfection should not be the enemy of progress in this context. It 
is fully accepted that achieving global consensus on information 
sharing cross-border is a hugely complex issue, but that should 
not deter likeminded nations, or groups of nations (such as the 
G7 or the “Five Eyes” Intelligence Alliance), from building bilateral 
or multilateral agreements to share aggregated SAR data relating 
to their jurisdictions in a single report that is filed simultaneously 
in multiple FlUs. Further discussion on bilateral and multilateral 
cooperation is considered in Section 4. International Cooperation 
and Capacity Building. 


Progress in policy discussions around bilateral/multilateral SAR 
filing should be supported by parallel collaboration on data 
standards and the development of common SAR templates that 
would help accelerate data integration and analysis, as well as 
the possible inclusion of unique identifiers such as digital IDs t 
identify cross-border activity on persons of interest, without 
sharing personal data where no activity/corresponding SAR 
exists. 


ie) 


In addition to avoiding geographical silos, it is also important that 
organizational structures within Fls - for example between AML, 


cyber and fraud teams - do not put barriers in place that 
undermine the development of a comprehensive understanding 
of criminals and criminal threats that operate across thematic 
silos. Expediting efforts to enhance data fusion across 
organizations is a key enabler in the development of a 
comprehensive global SAR. 


b. Beneficial ownership reporting transparency 


Background 
Transparency of beneficial ownership and the reporting of that 
data is a critical tool in fighting all forms of illicit finance, from 
fraud to money laundering and corruption. Transparency of 
beneficial ownership can also help promote prosperity by 
building trust and clarity for financial transactions and 
nvestment. 


Though the concept of beneficial ownership registries is 
embedded in FATF Recommendation 24 (R.24), there is uneven 
progress in implementation across the globe. Where 

it is made available, a common theme is that the data is held 
and maintained by a public body that lacks the mandate, as 
well as the necessary financial and human resources, to 
effectively assure the quality of the data. This issue needs to 
be addressed through both policy change and investment 
creating a single source of reliable truth. 


Though the FATF is currently consulting with its member 
jurisdictions and other stakeholders on amendments to R.24%4 
and while implementation and enhancement to registries 

are underway at various speeds across the globe, a few key 
issues should be addressed to enhance international coherence 
in the design and operation of beneficial ownership information 
reporting. Given recent developments such as the data leak 
around the “Pandora Papers,”’° it is evident there is a lack 

of transparency in the international system; countries should \ 
make reform in this area top priority in line with the 
commitments of the G20 and other international bodies. 


Recommendations 


First, Fils should not be primarily relied upon to verify the 
information in beneficial ownership registries, to act as 
gatekeepers, or to depend on discrepancy reporting as a means 
of validation. There should be increased emphasis on requiring 
the legal entities themselves (including corporate entities and 
other forms of incorporation such as, among others, trusts and 
partnerships) to satisfy CDD requirements in a verifiable way, 
with commensurate penalties for non-compliance. 


13 


The effectiveness of financial crime risk management reform and next steps on a global basis 


14 


Second, in order for the registry to be reliable, it is important 
to be clear in R.24 that the public sector stands by the contextual 


reference data they 


effective ris 
context, having sign 


management. The issue of rel 


compliance processes (e.g., CDD, and/or ongo 


across multiple insti 


tutions, potentially releasi 


provide, ensuring it is a source upon which 
the regulated sector can rely both practica 
integrity of the verification informa 


ly and legally ifthe 
tion is appropriate for 
iance is key in this 
ificant potential to reduce 


duplicative 
ing due diligence) 
ng significant 


capacity that could be refocused on higher value activities. 
Fls should not be expected to ensure the qual 


maintained in a beneficial ownershi 
reporting should not be relied upon 


Third, access to beneficial ownershi 
made available first and foremost 
legitimate purpose for needing this 
regulatory bodies, law en 
nformation and genuine 
are key considerations which shou 


to those wh 


data privacy/protecti 


ity of information 


p registry and discrepancy 
as a means of validation. 


p information should be 


ohavea 


information, such as FIUs, 
forcement and Fls. Security of 


on concerns 


d be considered when 


considering access to registries.?6 This will require coordination 


with and the cooperation of national agencies 


responsible for 


privacy regulation. Based on this, tiered access for legitimate 


interest by other stakeho 


ders beyond compe 


and Fls could be considered. 


tent authorities 


Fourth, it is important that further work is undertaken to 
ensure that inconsistencies in national approa 
ownership information accessibility and repor 
Operational burdens with little to no risk management value 


arise when countries imp 
to yield the same results. 


ches to beneficial 
ting are mitigated. 


ement different requirements that seek 
Country coordination on common 


standards would improve both efficiency and effectiveness in risk 


mitigation by Fls and would a 


financial system. It will also aid cross-border in 
and network analysis in FlUs if there were common fields/\ 


tandards that enab 


n 


FATF has a significan 


ed the registers to be 


include a regular revi 


re mitigated, includi 


t opportunity to enhance 


ew of registries to ensure 
ng the use of false documentation or 

inaccurate identities to hide beneficial ownership interests.” 
However, it is also incumbent on countries 
weak spots and address the issues noted h 


so further protect the global 


vestigations 


nitted together. 


the effectiveness 


of jurisdictional beneficial ownership registries by ensuring high 
standards are in place internationally through 
a 


R.24 which 
weak spots 


to act now to identify 
erein. 


The UK provides an interesting and positive example in this 


context. The UK registry - Companies House — has mapped out 
a clear strategy to transform its remit from that of a passive 


registry to one where it will be an active participant in the 


anti-financial crime community. Companies 


House will build 


capacity - both human and technological - to engage in the 
proactive analysis of data to identify and share strategic and 
tactical intelligence on crime. Critically, Companies House will 


itself take a degree of responsibility for the i 
verification of beneficial owners. 


= 


While organized criminals will indubitably re 


reforms by seeking new ways to try to undermine the integrity 
of the system, (e.g., using “mule directors”, acting as fronts 


to hide genuine beneficial owners), these ris 
by proactive information sharing by Compa 
emerging typologies and risk. As such, thes 


n 
e 

a welcome strategic repositioning of the role of the company 
m 


registry in the anti-financial crime ecosyste 


dentification and 


spond to these 


Ss can be mitigated 
es House around 
reforms represent 


putting beneficial 


ownership at the heart of the collective response to illicit finance 


in a way that can help substantially to prevent and detect the 
criminal abuse of company formation. Ambitious reforms like 


those proposed by Companies House shou 


d be monitored and, 


if successful might be emulated internationally. 


c. Data utility models 


Background 


It is vital that best use is made of the capacity that exists in 


the global financial crime ecosystem. Financ 


ial crime risk 


management frameworks globally should enable and encourage 


modernizations that have the potential to m 


inimize low-value 


activities so that capacity can be more usefully focused on 
other, mutually agreed, higher-value activities with greater 


potential to deliver positive outcomes. 


Data and information utilities are important 


in this context, 


which, for the purposes of this paper, we define as mechanisms 


that either allow duplicative processes to be 
on behalf of many (e.g., KYC utility), or which 


undertaken once 
allow siloed datasets 


to be brought together in information sharing utilities (both 
publicto-private and private-to-private), either through data 
pooling, or through the use of collaborative analytics, to 


enhance the efficiency and effectiveness of ris 
functions (e.g., a transaction monitoring utility 


also has significant potential 
mutualized data (a form of utility), at the hea 
prevention.”® 


management 
. Digital identity 


to be an important category of 


rt of financial crime 


Fulfilling KYC obligations might be considered an inefficient 
process when assessed at the whole-system level. Developing an 
approach that would allow this process to be undertaken once 


The effectiveness of financial crime risk management reform and next steps on a global basis 


on behalf of all stakeholders could release huge volumes of capacity 
for reinvestment in other activities, such as participation in PPP and 
investment in enhanced analytics. 


Anumber of jurisdictions have trialed the development of KYC utilities, 
most notably in the Nordic region, in Africa and in Singapore. Pilots 
to-date have identified significant complexities around issues such 
as the agreement of common standards between participants, the 
availably of “golden data sources” (and to what extent they can 
be relied on in a regulatory context), information technology, 

implementation costs, and the rationalization of legal complications 
around issues such as the processing of personal data. 


These challenges have sometimes slowed or stopped progress. 
However, they are potentially surmountable over time, especially if 
lessons learned through both successful and unsuccessful pilots 
are captured and shared widely and, with the encouragement of 
regulators and policymakers, are used to inform the development 
of future efforts to build innovative solutions to address this 
duplicative and resource-intensive element of the financial crime 
framework. 


There have been a number of interesting developments in the field of 
information sharing utilities since the analysis in 2019. For example: 


* Inthe Netherlands, through Transaction Monitoring Netherlands 
(TMNL), five major banks are piloting collective transaction 
monitoring of combined pseudonymized transaction data to 
identify unusual patterns of cross-bank activity relating to money 
aundering. The immediate goal is to enhance the effectiveness 
of the participating banks’ efforts against financial crime, with a 
potential end state being the development of an industry-wide 
utility performing transaction monitoring activities on behalf of 
the Fls involved. While TMNL is a private sector-led initiative, the 
banks have sought active cooperation with stakeholders in the 
public sector to build the TMNL platform. For example, detailed 
typological input has also been provided by the Dutch FIU. 7° 


nthe UK, the Tribank*? pilot pooled transactional data from three 
banks in pseudonymized form. This was successfully combined 
into a meaningful dataset over which centralized analytics could be 
pplied to reveal suspicious patterns of activity for further review 


* In Switzerland, a number of major banks are working together to 
establish a utility for sharing data for AML alert mitigation. The 
goal is to create a model that includes agreed systematic triggers 
which, in the future, would allow the banks to share KYCderived 
information to drive timely improvements in data quality and 
the effectiveness of operation models. A legal assessment was 


15 


The effectiveness of financial crime risk management reform and next steps on a global basis 


C 


concept 
AML alerts. The proof-of-con 
clients and alerts across ban 


expanded multi-ban 
2021 will test scalabi 
technologies to facilitate info 


pilot s 


In Denmark, the Ministries of 
have launched a project which inten 


of new typologies and enhance the 


ityandt 


s to enabl 


rmation sh 


Industry, J 


feasibility and value of estab 
platform that will enable Fis’ 


triage of alerts. 
ated for completion later in 
he value of 


dst 
ishing a central analy 


ndertaken to agree on the scope of the utility within current 
regulations and in accordance with existing customer terms 
and conditions. The initiative has undertaken a proof-of- 
leveraging transactions that 
cept identifies 


previously triggered 


overlaps between 
e the identification 
An 


privacy enhancing 
aring. 


ustice and Taxation 
o assess the 


tical 


transaction 


data to be enriched 


with law enforcement intelligence to improve the collective 


effectiveness of efforts to prevent and detect money 
aundering, VAT fraud, and oth 
is being developed under the auspices of the Central Bank, 
considering issues such as da 
and challenges and opportuni 


framework. 


regulated party. 


n Australia, an amending law 
introduces the opportunity for the regulated community to 
place reliance on KYC obtained from another regulated party. 
n order to obtain “KYC reliance” on another regulated party, 
n institution seeking reliance could undertake both initial 

nd ongoing due diligence on the KYC processes of the other 


to the AM 


Other countries testing information-sharing uti 
and the US. In the US, FIs wishing to explore information-sharing 
utilities have the distinct advantage over peers 
jurisdictions in that the information-sharing provisions set out in 
the USA Patriot Act enable bank-to-bank information-sharing “in 


the clear” in certain circumstances.** Being able 
unencrypted has the potential to simplify data i 


centralize 


As noted in Part 
announced that 
[Commercial Affairs Department] 


ied) 


implement] a 


warn each other 
such a uti 
mplify Singapore's collective abi 


analysis as well. * 


it is working in “c 


brigading institutional capabilities. 


16 


er financial crime. The pi 


ta privacy, technical 
ties within the existing legal 


ot 


feasibility, 


L/CFT Act and Rules?°, 


ties include Japan 


in most other 


to share data 
ntegration and 


1 of this paper, in Singapore, the MAS recently 

ose collaboration with the 

and a number of major banks, [to 
technology enabled platform for participants to share 
information on customers exhibiting significant risk red flags and 

of potential criminal activity”.** The development of 
ity is highly encouraging for the potential that it offers to 
ity to prevent and detect crime by 


As might be expected, all recent pilots have - to a greater or 


models from 
inc 


as legal unce 
as data priva 


more criminal ac 
for analysis. How 
challenges that, i 


the incompatibili 


SCca 


dIT platforms, 
ing can occur, as well 


esser extent - confirmed the fundamental hypothesis behind 
information-sharing utilities, which is that it is possible to identify 
tivity more effectively when data is brought together 
ever, the pilots have also revealed very significant 

f not addressed, have the potential to prevent 

ing up into “business-as-usua 
ude, for example, issues at the organizational level, s 
ty between data standards an 
should be tackled before any information-shar 


" approaches. These 


uch as 
that 


rtainty around the interplay between concepts such 


cy and information-sharing, 


cross 


border data sharing, 


tipping off customers regarding SARs filings, and reliance on third- 


party data (issues which are exp 
Financial Intelligence). *° 


of 


they 


when 


encouraged, 


Despite the inherent c 
remain a concept 
to the effectiveness of 
public and priva 
utilities to be truly inte 


ored throughout Section 1. The Use 


hallenges encountered in developing utilities, 
of potentially substantial transformative value 
the anti-financial crime framework, especially 
te sector insight is brought together to enable 
lligence-led and aligned with the prioritization 
of threats. As such, investment and innovation should be actively 


and further consideration should be given to these 


Recommendations 


First, in order to accelerate and support data uti 


topics across jurisdictions in the following ways. 


is important that policymakers and regulators provide a 
of certainty about the long-term value of 


of working. Take, for examp 


e, a transaction mon 


lity innovation, it 


degree 


investing in new ways 


which four banks participate. In this case, the long-term 


system of the u 


crime by ana 


their commu 
example, 
detection 


ong-term value 


that 
of suspicion 


Both the pub 


tility, is an enhanced abilit 
yzing transaction data from 
to Fls is both social (a gre 
nities and clients 
in the future ifa 


set of agre 


ic and private sectors bene 


and commercial ( 


are met, participants cou 
four transaction-monitoring capabilities i 


y to prevent and detect 
e institutions. 
lity to protect 
the possibility, 
ed thresholds around 
d rationalize their 


multip 
ater abi 


nto one). 


itoring utility in 


value to the 


The 


for 


fit if the utility is successful; 


but development risk currently lies only with the private sector, 


which genera 


y bears the costs of develo 


pment and del 


as - for example - legal risk, without any 


successful de 
Regulators and policyma 
a degree of ri 
legal obligations if the uti 


thus helping 
and accelera 


framework overall. 7° 


ivery as well 


ong-term certainty on how 
ivery might impact future regulatory expectations. 
kers should be prepared to con 
Sk (for instance by committing to changes in certain 
lity meets an agreed-upon set of criteria), 
encourage private sector investment in util 
ting the delivery of a more effective financial crime 


sider sharing 


ity models 


The effectiveness of financial crime risk management reform and next steps on a global basis 


Second, the use of regulatory sandboxes (e.g., the sandbox run 

by the Financial Conduct Authority (FCA) in the UK ) is important 

n this context. There are already leading examples of information 
regulators and financial conduct regulators using the sandbox 
concept to help encourage innovation. When considering 
nformation-sharing utilities, however, it will often be the case that 
participants will come up against issues that are relevant to both 
types of regulators (and potentially issues relating to the handling of 
FIU data as well). 


As such, it is important that—at a minimum—information and 
financial crime regulators, supervisors, and examiners work 
closely together to help create the conditions in which innovation 
can flourish. They could also consider working together on the 
development of experimental collaborative sandboxes through 
which all potential legal and regulatory challenges relating to 
information-sharing utilities could be considered and addressed 
comprehensively to help accelerate innovation. For this to be most 
effective, financial crime regulators themselves may need to invest 
in appropriate expertise in order to facilitate the acceptance of new 
innovation. 


any of the challenges around utilities relate to the need to bring 
together siloed data. However, there are points in the ecosystem 
where data is already aggregated to various degrees including, for 
example, the national payments architecture, national settlement 
systems, and the correspondent payments networks. Stakeholders 
in the financial crime ecosystem should collaborate to explore 

ways to test how centralized financial crime analytics could be run 
across existing points of data aggregation (e.g., a national payments 
architecture) to identify and disrupt suspicious patterns of activity 


Third, there should be further exploration on points of aggregation. 


efficiently and effectively - including patterns that could not be 
identified by analyzing data within organizational silos. 


tis highly encouraging that the use of the payments architecture 
to tackle crime is noted as an ambition by some policymakers,*® 
although the implicit focus is on using the payments architecture 

to “design out” fraud. This is an entirely laudable aim and an 
understandable priority, but public and private sector stakeholders 
should seek to ensure that the potential dividends of investing in 
centralized analytical capabilities are fully explored in the context 
of tackling a much wider set of economic crimes, including money 
laundering, tax evasion, and other predicate offenses. 


d. Public-private partnerships 
Background 


A PPP - a collaboration between Fls, law enforcement, policymakers, 
and the regulatory community - has become an important and 
growing component in global financial crime frameworks. A detailed 
analysis of the rationale behind the establishment of PPPs, and the 
value they can add was included in the 2019 white paper. 


Since the inception of the UK Joint Money Laundering Intelligence 
Taskforce (JMLIT) in 2014, PPPs to enable the sharing of intelligence 
and information have been established in over twenty countries 
across Asia Pacific, the Americas and Europe. In addition, a number 
of “single issue” PPP initiatives have been established, bringing 
diverse stakeholders together to improve the response to specific 
threats such as wildlife trafficking. Meanwhile, Europol’s Financial 
Intelligence Public Private Partnership (EFIPPP) has continued to 
develop its role as the first multilateral PPP. 


17 


The effectiveness of financial crime risk management reform and next steps on a global basis 


The growth in PPP has also been encouraged by the FATF in policy 


statements and through the Mutual Evaluation 
sus that by developing fra 
enable more intelligence and insight to flow be 
is possible to disrupt malign actors more effec 
prevent criminal misuse of the financial system 
relationship between sta 
ourage and enable parties to share as much 


iS now broad consen 


begun to change the 
frameworks that enc 


as possible, rather than as little as is required. 
global developments in PPP are a fundamenta 


opportunities to do more remain. 


Recommendations 


First, PPP models have evolved different 
with the priorities, types of information a 
ways of working, and governance and lea 
particular circumstances and characteris 
the PPP has been established. 


While PPPs are currently at different poi 


process, and there 

meworks that better 
tween parties, it 
tively and better 
. Critically PPPs have 
eholders, building 


However, while 
ly positive story, 


y in different jurisdictions, 
nd intelligence shared, 
dership all reflecting the 
tics of the country in which 


nts in their development, 


national and supranational policymakers could encourage PPP 
models to develop over time in several ways, including: 


* From a policy perspective, PPP should be embedded within the 
financial crime policy architecture at the national level to ensure 
that insight and input from across the stakeholder community is 
captured and used to drive development of effective legislation 


and regulation. 


* At the strategic level, PPPs should be used to drive exponential 
growth in the development and distribution of strategic 
intelligence products and typologies. This intelligence should be 
shared at scale to help inform the effective application of the 
risk-based approach and to drive consequential improvements in 
prevention, detection, and reporting. 


At the tactical level, PPPs shou 


d find ways to share operational 


intelligence between stakeholders to expedite investigation and 


drive outcomes. Tactical 
governance frameworks 


information-sharing demands robust 
and clear legal gateways, but it is vital 


in driving both effective outcomes against priority threats, and 


in providing the building 


typologies. 


Second, PPPs of all kinds h 


blocks in the development of good 


ave demonstrated their value. They 


have built trust and collaboration across stakeholder communities 


and improved the focus an 


d quality of SAR reporting. PPPs have 


empowered the risk-based approach, provided stakeholders with 
access to new intelligence and better insights, and helped to deliver 


18 


positive outcomes efficiently and effectively for all sides. They should 


no longer be thought of as a policy experim 
be considered a key component of any heal 


framework. As such, it is important 
prioritized and resourced within bo 


Third, Policymakers could consider h 
tivized through regulatory and supervisory frameworks, with a 


incen 


ent and should instead 
thy financial crime 

that PPPs are appropriately 

th the public and private sectors. 


ow participation in PPPs can be 


focus on reduction/detection of economic crime and the provision 


of highly usefu 


PPP has been recognized by policymakers at 


As such, participation remains a vo 
addition to regulatory obligations. 


PPP, when balanced against meetin 
This undermines PPP growth, restri 


working (such as the development of data uti 


information to law enforcement. While the value of 


both the national and 
supranational levels, participation by members of the regulated 
sector is not formally acknowledged within regulatory frameworks. 
untary activity undertaken in 


The absence of regulatory recognition acts as a limiting factor on 
the amount of time and resources that institutions can invest in 


g wider regulatory obligations. 
cts investment in new ways of 


ties), and inhibits the 


ability of PPP to deliver on its full potential. Reforms under way or 


being considered in both the US an 
answer. 


dthe UK 


The US AMLA establishes the concept of nati 
supervisory framework increasingly focused 
highly useful information. Simultaneously in 

consultation on the Money Laundering Regu 
views on the concept of high and low value activities in the system— 
which one may assume—once agreed, would be supervised against 


accordingly. 


Recognition that participation in a PPP 
commensurate supervisory expectatio 


areas of low value to areas of 


institutions to direct increasing amoun 

supporting PPPs in all forms, from developme 

nd investment in innovation such 
ti 


typologies to operational support a 
as the development of bulk data-sh 


This, alongside continued progress 
reform (e.g., to introduce national p 


information sharing private-to-private, 


border as discussed more broadly i 


aring utili 


n that 


ts of ef 


in associa 
riorities an 
public 
n the previ 
section), could begin to enable a significant sh 


may provide part of the 


nal priorities, anda 
n the production of 


the UK, HM Treasury's 
lations (MLR) seeks 


is a ‘high value’ activity (with 
focus is moved from 
high value) could enable regulated 

fort and energy toward 


nt of policy and 


es. 


ted areas of legislative 


dto enable more 


to-private and cross- 


ous topics of this 


ift in allocation of 


resource within the regulated sector from tick box compliance to 
intelligence-led collaborative activities of high value to the delivery of 
outcomes across the financial crime framework — including PPP. 


The effectiveness of financial crime risk management reform and next steps on a global basis 


Fourth, PPP leaders should consider how they can tailor 

engagement with members to build a model that finds the right 
balance between data coverage and agility. As PPPs establish and 
grow both through the passage of time and the delivery of reforms 
such as those described above, there will be natural pressure to 
expand membership. This pressure exists for a range of reasons 
including that increasing membership can be used as a proxy 
measure of success; that growing membership reduces perceptions 
of unfairness or favoritism; and, simply, that it instinctively seems 
ogical that a greater number of members means more access to 
intelligence and better insight. 


However, growth also brings challenges. A wider membership can 
increase governance and administration overheads. It can also make 
obtaining a consensus difficult, which can inhibit innovation, and 

it can divert focus from core priorities through pressure to ensure 

a steady flow of cases or typologies that are sufficiently relevant 

to all. Most fundamentally, growth for growth's sake can impede 

the development of trust. For example, in the context of tactical 
information-sharing partnerships, law enforcement may be less 
willing to share sensitive case data as membership expands. 


An effective PPP model could include tiered membership, blending 
light touch engagement across a broad range of institutions and 
sectors, with a smaller set of deeper relationships with a number 

of core members. Membership of the core would need to reflect 
agreed priorities and could be cross-sector where required (€.g., 
where scams are a priority threat, engagement with online platform 
providers would be key to knitting the online and financial networks 
together). The core would also need to be sufficiently flexible to 
respond to changes in the market (such as the emergence of virtual 
assets) but would almost certainly include the relatively small 
subset of Fls that in most jurisdictions sit across the vast majority of 
financial information and intelligence in the ecosystem. 


Due to their scale, these organizations would likely have a touchpoint 
most cases, the capability to conduct high-quality analysis and 
vestigation at pace in support of the partnership, and the capacity 
to back the development of new and more effective ways of working, 
such as physical co-location and the development of innovative 
approaches to bulk data-sharing and collective intelligence-led 
analytics. By keeping the core at a manageable size, the group 

would be more agile in its response to threats and development of 
nnovation. 


3 5. 


It would be imperative in such a model that insights obtained by a 
core group working closely together were routinely captured and 
shared with the wider regulated sector. This would help to manage 


perceptions of unfairness and inform the effective application of the 
risk-based approach more widely and enable collective prevention 
at scale. 


Fifth, public and private sector stakeholders should continue to 
drive efforts to encourage and enable PPPs to collaborate cross 
border. Similarly, it is important that where single issue PPPs exist, 
they work closely with national PPPs in order to share insights 
against potential areas of overlap (e.g., routes and techniques 
used in trade-based money laundering and environmental crime) 
and ensure that shared learning is not lost by looking at issues in 
isolation. 


Sixth, PPP participants should explore the development of digital 
typologies. By combining traditional law enforcement skillsets with 
participation from technologists, PPPs may be able to move from 
paper-based typologies to the creation of digital typologies, coded 
as a set of rules, that could be more easily and quickly ingested into 
the transaction monitoring systems of a wider range of institutions. 
This could help to ensure that the biggest collection and detection 
capability in the financial crime ecosystem (i.e., the transaction 
monitoring systems at Fls) was better able to more accurately and 
quickly prevent, detect and report crime. 


va) 


e. Data protection and security issues 
Background 


Issues concerning tensions between data protection and information 
sharing are not new and cut across nearly all areas outlined in this 
section relating to the use of data and financial intelligence. They 
also concern other relevant areas of discussion, including issues for 
risk prioritization in Section 2 and the adoption of new technology 

in Section 3. Real or perceived friction between data exchange 
and rules related to data protection, privacy and confidentiality 

are recognized as potentially restricting or prohibiting information 
sharing on matters concerning money laundering, terrorist financing 
and other threats. However, while the protection of customer/ 
personal data and the right to privacy are of unquestioned 
importance, the upholding of such principles does not exclude 
sharing information on illicit financial activity in a safe and secure 
way. Getting this balance right is therefore critical. 


To make progress in overcoming such difficulties and to broaden the 
ability to share valuable information amongst Fls, law enforcement, 
and regulators on a cross-border basis a few key issues should be 
considered. 


19 


The effectiveness of financial crime risk management reform and next steps on a global basis 


Recommendations 


First, the FATF made substantive progress in this area when it 
adopted revisions to FATF Recommendation 2 (R.2) on national 
cooperation and coordination. The amendments expanded 

the Recommendation to include information sharing between 
competent authorities and emphasized that cooperation should 
include coordination with the relevant authorities to ensure the 
compatibility of AML/CFT requirements with Data Protection and 
Privacy (DPP) secrecy rules and other similar provisions (e.g., data 
security/localization). *° 


Once enacted jurisdictionally, this change should help to make 

sure AML/CFT and DPP rules are accordant and should assist in 
facilitating exchange of information within the private sector and 
between governments and the private sector. The FATF itself is 
encouraged to continue to rigorously review national adoption 
through criteria which reviews efficacy in line with the FATF’s overall 
objectives. The utility of any Recommendation change is only as 
good as both its practical application in national rulebooks/guidance 
and its actual, measurable results in line with both the letter and 
spirit of the revisions. 


In this regard, there should be further focus on whether the 
outcomes of cooperation have led to changes or clarifications 
in laws/regulations and material growth in gateways to data 
exchange. This will likely be the ultimate test as to whether the 
Recommendation actually supports real progress. *° 


Second, there should be a wider, global focus on addressing the real 
or perceived tensions between data protection laws and information 
exchange for financial crime matters on a cross-border basis, and 

in developing a clear mutual understanding between stakeholders. 
The FATF, for example, has found there is a noted lack of interaction 
between national and international AML/CFT and DPP authorities. 
Such lack of coordination and cooperation might also impede the 
efficacy of R.2, noted above. 


Building on the national-level dialogues mandated through R.2, 
support should be built on a global basis for an AML/CFT/DPP Forum 
organized through the FATF, which brings together data protection 
and financial crime authorities across countries to work on ways 

to facilitate cross-border exchange of information. The outcome of 
such a process could drive principles that help reconcile differences 
in approach and develop solutions leading to determinations of 
equivalence, or in appropriate cases, mutual recognition of laws 

and regulations aiming to achieve the same purpose of protecting 
against financial criminality while upholding data protection and 
security. This may lead to an enhanced, meaningful exchange of 
financial crime information, not just between governments but also 
between Fis, between governments and Fls, and within Fls across 
jurisdictions. 
FATF could prioritize this work through its current project related 

to data pooling, data analytics and data protection.** The FATF 
have taken a vital step through that project in recognizing that 
AML/CFT and DPP are both significant public interests that serve 
important objectives, which are neither in opposition nor inherently 
contradictory.*? Indeed, they can be complementary, with the 
greater the targeted intelligence shared, the more precise the 
reporting can be. This would lead to less intrusion into private 
sources and less overreporting of non-pertinent information. 


The FATF have also recognized that while DPP laws may differ 
between each jurisdiction, there is a trend toward convergence.** 
This trend could be capitalized upon through a cross-border 
AML/CFT/DPP Forum that supports the objectives noted herein 
with outcomes that can be relied upon as an optimum means for 
enhancing legal gateways. 


It is also important to reconcile work at the FATF level on these 
issues with work underway at the behest of the G20 concerning 
enhancements to cross-border payments. The G20 building blocks 
on how payment system improvements could be achieved includes 
reviewing the interaction between data frameworks and data 
protection in conjunction with AML/CFT requirements. The building 
blocks report raises the difficulties that can come from underlying 


20 


The effectiveness of financial crime risk management reform and next steps on a global basis 


legal frameworks and the challenges coordinating and securing 
support for alignment with international rules, standards, and 
cooperative supervision and oversight arrangements. Addressing 
these impediments through a global AML/CFT/DPP Forum may help 
achieve the wider objectives of the G20 through greater alignment 
and clarity in laws and regulations across borders. 


Third, the issues of data protection and financial crime information 
sharing should not be discussed in siloed conditions. The wider 
matters of privacy are often considered issues of human rights and 
should be reflected in the broader dialogue involving the general 
public whose information is held across Fls and by competent 
authorities. *° 


As such, it is extremely important for key actors at both the public 


nd private sector levels to engage with 


civil society in a proactive 


a 
discourse on the benefits that can be derived from appropriately 
sharing information on financial crime matters within the context 
of DPP frameworks. This dialogue should take two forms: first, an 
assurance that data privacy and data minimization principles wil 
upheld to the highest degree while achieving the goals of protecting 
society and financial stability from the effects of financial crime; 
and second, addressing general concerns that information-sharing 
could lead to further financial exclusion of segments of society, 
exacerbating de-risking issues which have been at the forefront of 
policy discussions for many years. 


The second point is particularly important to address in the context 
of emerging markets, and greater care should be taken in ensuring 


that the benefits of information sharing are taken into consideration. 


For instance, it has been noted that improving data sharing on 

a cross-border basis can actually lead to more targeted risk 
assessments by Fls, thus helping to deter wholesale reassessment 
of client coverage based on inadequate information.*® The Financial 
Stability Institute (FSI) has emphasized that improved cooperation 
on information sharing can help to reduce unwarranted de-risking, 
which would further aid in enhancing financial inclusion.*’ 


As noted in Part 1 of this paper, Singapore has taken a highly 
measured approach to assessing and addressing information- 
sharing challenges in their jurisdiction, and a focus on the 
concerns of civil society is very much at the forefront of delivering 
improvements to the financial crime framework.*® As policymakers 
around the world further examine the means of tackling the critical 
issues concerning DPP and AML/CFT, incorporating civil society 
into the discussions will help ensure the objectives of all parties are 
addressed while moving toward effective change for the benefit of 
society and stability. 


2. Risk prioritization 


Background 


The relative maturity of financial crime frameworks across different 


jurisdictions will vary, as will leve 


s of trust and confidence between 


system stakeholders. In jurisdictions that are less mature, the focus 
of policymakers, regulators and supervisors both domestically 
and internationally should remain on ensuring the effective 


implementation of global standards into na 


tional AML/CFT 


frameworks to build a solid foundation for the risk-based approach. 


In countries with more mature financial crime framewor 
there is a growing consensus 


that establishing national priorities 


- which are the money laundering and terrorist financing risks to 


which a country is exposed - can help shi 
AML/CFT programs from maintaining techni 
tcomes-oriented approach.*? As systems ch 
mproves across jurisdiction 


risk-based, ou 
effectiveness | 


s, however, 


ft the primary focus for 


cal compliance to a more 
ange and 
s, considerations such as 


these should naturally follow, and such a shift should be supported 


at the internat 


Specifically, a risk-based approach focused on national pri 
te sectors with detecting and reporting 
more meaningful suspicious activity aligned to areas of im 
t. Indeed, according to the FATF, countries 
ML) 


assist the pub 
to the nationa 


and terrorist fi 


implement anti-money lau 


ic and priva 


governmen 


should “identify, assess and understand the money laundering 


nancing (TF 


these risks are properly understood, countries should be able to 


ional level, including through the FATF. 


risks to which they are exposed. Once 


inclusion. ° 


measures that 


help mitiga 


nsome countries, such as the US, governmen 
established official national priorities. For example, the US 
Department of Treasury's FinCEN recently published national 
priorities? that are composed from longstanding threats (e.g, 
international terrorism) and emerging threats ( 
are supplemented by strategic documents.°? 


te these risks."°° The publication of the 
FATF Guidance on Risk-Based Supervision also makes it clear that 
a risk-based approach is less burdensome on lower risk sectors 
or activities, which is critical for maintaining or 


ndering and counter terrorist financing 


increasing financial 


ts have already 


nasimilar spirit, 


portance 


orities can 


e.g., cybercrime) and 


Singapore publishes its National Risk Assessments, and the financial 


regulator uses its supervisory activities and its PPP to focus Fls on 


priority risks including driving the use of data analytics to strengthen 
detection and reporting in these areas. 


21 


The effectiveness of financial crime risk management reform and next steps on a global basis 


In order to 


identify, evaluate, and mitigate risks associated with the 


national priorities, Fils should consider how they will adjust their risk 
assessment processes to focus more closely on applicable priorities 


and more rapidly understand and incorporate new information 
received from law enforcement and other sources in the future. 


Incorporating priorities into AML/CFT programs will likely require a 


greater focus on understanding s 
nd how they may intersect with the 


priorities a 


Once an Fl understan 
the national priorities 
on higher-risk custom 
Fls should consider 
intelligence into their 
basis and national au 


to develop metrics an 
programs align to the 
consider how the effe 
measured in order to 
is highly useful, and h 


Reallocating resou 
AML/CFT program 


rce 


directed toward higher-ris 
the risk profile of an Fl and 


This will require the Fl 
CFT 
When reallocating 
activities, the 


producing highly usefu 


To take advan 


data-driven risk assessme 


to law enforcement. It 


program changes 
focus and resources from lo 
FI will need to demonstrate how 
| information for law enforcement. 


_it w 


A 
thori 


prio 


is 


de 
ow 


s wil 


tob 
inc 


tage of this opportunity, Fis shou 
a consistent, repeatab 


ea 


ers and activi 
how they will incorpora 
L/CFT programs an 


d examples to demon 


ill need the flexibi 


ity 


ted 


ties will need to help 
nts. It is likely tha 


rities and 


ate sectors. 
also need to be add 


customers and acti 
the risks associated 


uding the reallocatio 


e more willing and agi 


pecific threats related to applicable 


Fl's business activity. 


ds how it is impacted by risks associated with 


to refocus resources 


ties consistent with its risk profile. 


dditional data and 


d controls on an ongoing 


enable Fls to perform 


t most Fls will also need 
strate how 
the associated value of reporting 
important that the global standard setters 
ctiveness of Fls, FIUs and examinations will be 
termine whether the information produced 
feedback will be shared across the public 
(e.g., FIUs to FIUs) and priv 


their AML/CFT 


ressed. An effective 


ensures more attention and resources are 


vities, consistent with 
with the priorities. 

e in making AML/ 

n of resources. 

wer- to higher- value 
the resulting shifts are 


nd defensible a 


Id consider adopting 


pproach to procedural 


changes that can be applied across the AML/CFT program and which 


satisfies exam 


with appropriate governance, documenta 


to realigning resources on 


concept to work, FIs, | 
will 


awe 


need to be aligned on 


tion, 
more value-added a 


the local govern 


definition of effectiveness. 


However, there are clear chal 
ing down low-risk management value activities or lower national 


dia 


enges that could 


iners and auditors. A change management process 


and sign off will be key 
ctivities. For this 


nforcement, regulators, and supervisors 
ment priorities and the 


inhibit Fls from 


priorities and the reallocation of resources. Within some national 


frameworks, there is a divisio 
authorities setting the prioriti 


n between the law enforcement 
es and the supervisory authorities 


responsible for examining a Fl's compliance with regulations. Based 


on current practices, FI's will 


22 


ikely have to dem 


onstrate to their 


internal auditors and examiners the reasoning behind why they 
stopped performing activities that they previously included in their 
policies and procedures, and why their programs remain compliant. 
Some Fis might be reluctant to stop activities (even ones producing 
little value, such as halting the review of alerts that do not identify 
suspicious activity) due to the concern of regulatory critique. 
Additionally, some Fils might determine that the burden of (and the 
time spent on) documenting why a particular activity was stopped is 
too onerous in terms of general resource allocation. 


As such, measuring effectiveness and enhancing the supervisory 
approach, including establishing clear guidance and expectations, 
will be critical. Although the risk-based, priorities-focused approach 
is a welcome reform, nothing will actually change until the 
supervisory and examination approach changes. It is critical that law 
enforcement, examiners, auditors, and other program evaluators, 
including Fls themselves, are on the same page in how to measure 
and evaluate AML/CFT program effectiveness. 


Examiners may need to consider shifting from utilizing a “check-the- 
box" supervisory approach (e.g., checking if the FI followed every 
step listed in its policies and procedures) to evaluating whether 

the Fl’s AML/CFT program is producing highly useful information 

for law enforcement and is managing and mitigating threats using 

a risk-based approach. For instance, examiners could assess the 
overall quality of the Fl’s policies and procedures instead of checking 
whether every element within the procedures was met, including 
elements that produce low-risk management value. 


Examiners could also consider assessing the effectiveness of the 
Fl's threat assessment and how effectively the FI integrated the 
applicable priorities into the Fl’s AML/CFT program. For instance, 
examiners could assess how the threat assessment informed 
adjustments within the AML/CFT program such as whether the FI 
reallocated resources toward priority areas and how the FI adjusted 
its KYC and transaction monitoring processes based on outputs 
from the threat assessment. 


nterms of adjustments to KYC processes, examiners could consider 
evaluating how the FI enhanced its onboarding, risk rating, periodic 
reviews and offboarding processes based on the level and type of 
threat exposure (e.g,, if there is a high cybercrime exposure, an FI 
should consider collecting IP addresses and incorporating them 
uring KYC and transaction monitoring reviews as appropriate). In 
ddition, examiners could evaluate how information collected during 
nboarding (e.g., nature and purpose of the account) is used to 
itigate exposure to risks based on the priorities. Also, if fraud is a 
ational priority, examiners could assess how information is shared 
etween the Fl’s AML and fraud departments if they are separate, 
istinct departments within the Fl. 


30092 


On. 


Examiners may a 


Iso consider evaluati 


The effectiveness of financial crime risk management reform and next steps on a global basis 


ng the types of alerts 


generated that are aligned with the priorities; how trends from SARs 


are used to enha 


nce the Fl's overall A 


L/CFT program; the quality 


of the SARs filed (e.g., whether the report provides law enforcement 


with sufficient information to assist an 


feedback from FIUs on SARs 


is acted upon to enha 


investigation); and how 


nce future SARS 


or build on existing networks where a subject is confirmed to be 


of interest. Additi 
financial crime ri 


As such, in order 


focused approach into the A 


additional consid 


training, feedback loop/in 
assessments, demonstra 


pilots. 


sk managem 
and associated risks to th 


Oonally, examiners cou 
ent trainings on th 
e Fl. 


to effectively incorporate a ris 


L/CFT framework, th 


eration given 
formation sharing on 
ting a 


the 


Recommendations 


First, it is important th 


based approach 
technical require 


d evaluate the quality of 
e applicable priorities 


-based, priorities- 


ere should be 


to the following areas: examiner 


priorities, threat 


ignment with national priorities, and 


at supervisors examine Fls by using a risk- 
focused on the priorities rather than solely on 
ments. If a risk-based, priority focused approach 


is agreed upon by the public and private sectors, examination 


materials and gui 


ied) 


exams and, most 
examinations. Ad 
updated instructi 


In addition 
help ensure that 
priorities are fo 


would gain 


exams are used i 


Second, streng 
on the priorities 
needs to conti 


reats re 
mation-shari 
statutory roots.°” 
have leeway 
in 


typologies. 


pproach, as Fls use th 


to retraining, an exam 


lowed. By spendi 
financial intelligence un 
an awareness of how the 


thening 
betwee 
nue to be 
ts. To have an effect 
ators, law enforcem 
ated to the p 


debooks will need to be updated 


impo 
ditionally, exam 
ons. 8 


iner secondment 
r examination 
ng ti 
it or workin 


prope 
me embedde 


information g 


n furthering the nati 


the feedback 
n the priva 
a 
ve AML/C 
ent, and F 


oop and infor 


FT framework, it 


ng between public and private ent 
Itis paramount that law enforcem 


processes aligned w 


onal priorities. 


to reflect the new 


ese materials to prepare their programs for 
rtantly, examiners use these materials during 
iners will need to be train 


ed on the 


m would 
ith 
d at the national 


progra 


g at an Fl, individual examiners 


eaned from their 


mation-sharing 


te sector and law enforcement 
focus of national and regional reform 


is necessary that 


s effectively share information 
riorities. Typically, the architecture for 


ities has domestic 
ent agencies 


in prudently exercising the legal authority to share 
formation on threats related to the national priorities or that 
gateways be developed to do so. This will create a positive feedback 
oop where private institutions and the public sector, particularly 
aw enforcement, can continuously share guidance on threats and 


Addition 
priority 
(NGOs), 
mechan 
identifyi 
For example, Fls cou 
received 
procedures, transac 
emerging patterns a 
Again, legal informat 
where facilitation of 
expectations on the 
understood by all ac 
the information rece 
programs. 


Third, there needs to be an 
processes to focus more on 
ll need to adjust their tradition 
to identify and unders 
e€ national priorities m 
ew threats will emerge, the Fl’s 
ogy should be agile, stra 
corporate information fro 
r sources instead of mirrori 


wi 
the use of threat ass 
CFT risks associated 


th 


en 
wide risk assessmen 
and focused on data 
outcomes.”°° 


Based on informatio 


type of predicate offen 


the 
with 
offe 


types of money | 


nses COU 
and services 0 
country as cou 
funds.°? Addi 
fraud, Fls will n 
and expertise 
their financia 


ffered 


Fourth, there 
public sector o 
the prioriti 
of an Fl's fi 


es. T! 


effectiveness. 


PPPs; the time 


existing threats will evolve and n 
reat assessment me 
and structured to quic 
forcement and othe 


eed to assess 
from across the organiza 
crime reporting to law enforcement. 


Id incorporate h 


nd file reports o 


this data exchan 
impact of the in 


ived to iden 


adj 


essmen 
with th 


US 


thodo 
lyin 


t which 
,docum 


n provid 


aundering/terro 


the underlying predicate offenses; 
d occur based on the types of customers, produc 
; and to identify the relevance of the 
ination of the laundered 


by the F 


ntry of origin/transit/dest 
tionally, for priorities like cybercrime, corruption an 
how to leverage additional intellige 
tion to improve the valu 


n how AML/CFT program 


nancial crime risk manageme 
priorities to help drive a risk-based approach and demonstrate 

Based on the Fl's size, complexity, customer base, 
and products and services offered, som 
that could demonstrate effectiveness in 


ge is inh 


rist 


tab 


ate 


formatio 


ished 
could 


la 


ibited. H 


ore 


entation, and process ra 


ally, where the development of a clear understanding of 
threats requires input from non-govern 
they should be engaged through es 
isms to share actionable learnings that 
ng and reporting on activities associ 
uman trafficking 
from NGOs into their AML/CFT prog 
tion monitoring rules) in order to identify 
n human trafi 


mental organizations 


PPP 
assist Fis with 


d with priority areas. 


trends/red flags 


ms (e.g., onboarding 


ficking activity. 
ion sharing gateways need to be considered 


owever, clear 


n sharing should be 
tors and particularly regulators who may use 
tify unexpected gaps in AML/CFT 


ustment of risk assessment 
threats associated with the priorities. Fls 


al risk assessments and incorporate 


tand the AML/ 
readily. Since 


ightforward, 
m law 


ng the “enterprise- 
tends to be very long, complex, 


ther than 


ed by law enforcement, NGOs and 
other Fls, an Fl could use a threat assessment to understand th 
ces associated with the priorities; understand 
financing cases associa 
to assess how the predi 


e 


ted 
cate 
ts 


d 
nce 
e of 


is aneed to develop a shared understanding with the 
s will be evaluated based on 
here are several ways that the day-to-day operations 
nt program can use national 


e metrics or examples 
clude: participation in 
iness of responses to law enforcement and relevant 


23 


The effectiveness of financial crime risk management reform and next steps on a global basis 


government authorities (e.g., responses to court subpoenas); SARs the working group should publish a report on the lessons learned, 
filed related to the priorities; recognition from law enforcement provide leading industry practices, and make recommendations for 
related to the priority areas; and employee participation in trainingin — regulatory change. 

applicable priority areas.°° 


Both supervisors and Fls need to calibrate the respective goals 
of their supervision and AML/CFT programs to produce highly 
useful information - aligned with the national priorities — for law 
enforcement. Supervisors could achieve this by providing case 
studies as examples to demonstrate how an effective AML/CFT 
program should incorporate the national priorities. One method 
could be through national FIUs producing domesticfocused case 
books like the Egmont Group's Best Egmont Case Award for the 
benefit of all domestic Fls and stakeholders.®' The cases could 

be sanitized and aligned with the national priorities, providing Fls 
with technical assistance, training, information exchange related to 
leading practices, and developing trends in AML/CFT. These case 
books can then be shared with the international community through 
PPPs and international organizations with a level of detail that is 
helpful to actually accelerate building effective monitoring rules/ 
scenarios to identify activity. 


Fifth, there is a need to provide a platform to pilot, evaluate and 
refine the implementation of priorities into AML/CFT programs. The 
global AML/CFT community, including supervisors and examiners, 
should embrace pilots and a regulatory sandbox approach for 
evaluating potential new risk governance and compliance practices. 
The development, adoption, and implementation of a risk-based, 
priority focused approach will take time, and new risk governance 
and compliance practices should be developed to effectively address 
the national priorities. A pilot exercise would help facilitate the 
responsible development of new risk governance and compliance 
practices by Fls, and new examination approaches and procedures 
by examiners. 


National and local governments could consider developing AML/ 
CFT priority pilots to allow a cross-sector participation of institutions 
to develop and implement the approaches for incorporating the 
national priorities into their AML/CFT programs. In doing so, the 
selected Fis would have an opportunity to reallocate resources and 
staff to higher-value activities while collaborating with examiners and 
law enforcement who can provide real-time feedback. By focusing 
on areas where two or more stakeholders are involved (e.g., Fl and 
examiner, or two Fls for information sharing), the public and private 
sector can better identify and address barriers that exist between 
stakeholders. 


Throughout the pilot (which is another form of PPP), Fls, law 
enforcement and regulatory stakeholders should consider 
participating in a working group to share feedback on the pilot 
design, examiner evaluation process, and FI effectiveness in 
addressing national AML/CFT priorities. At the conclusion of the pilot, 


24 


The effectiveness of financial crime risk management reform and next steps on a global basis 


3. Technology and innovation 
Background 


The challenges and opportunities inherent in the use of innovative 
technologies such as machine learning and advanced analytics were 
considered in the 2019 paper. Since that publication, the use of 
innovation to improve the overall effectiveness of financial crime risk 
management programs and disrupt illicit flows in high-risk areas has 
continued. Progress has been made in some jurisdictions, but also 
at the international level, in issuing guidance, statements of support, 
and in some cases passing legislation around emerging technology, 
with an overall goal of enabling innovation to enhance systemic AML/ 
CFT effectiveness. 


> 


The US AML Act, for example, makes innovation and the adoption 
of innovative approaches a regulatory imperative (e.g., ‘NextGen’ 
models that leverage behavioral analytics and machine learning 

to improve the effectiveness of financial crime monitoring and 
investigations). Innovation has also been encouraged in a number 
of countries through the use of regulatory ‘sandboxes’ that provide 
a safe space in which new approaches can be tested. The Financial 
Conduct Authority (FCA) in the UK has gone further, annually hosting 
a series of Financial Crime Tech Sprints to promote the use of 
emerging technologies that could combat money laundering and 
financial crime more effectively. 


Innovative information-sharing consortiums have received a 

degree of regulatory encouragement in Europe, specifically in 

the Netherlands with the development of an AML transaction 
monitoring consortium (TMNL), and in the Nordics through the 
establishment of a Joint KYC utility. In Singapore, the MAS has 
encouraged and supported the effective adoption of AML/CFT data 
analytics by Fls. These include solutions that apply machine learning 
and natural language processing techniques to replicate or enhance 
operationally intensive processes, such as analyzing name screening 
hits, priority ranking of transaction alerts for analyst reviews, and 
network linked analysis to assess higher-risk activities. 


Critically, at an international level, the German Presidency of the 
FATF has prioritized digital transformation in tackling AML/CFT. A 
coordinated, global focus on advancing technology in this area can 
help build coherence in approaches across jurisdictions and assist 
in the development of best practice in driving effectiveness and 
improving outcomes. 


However, challenges remain in the adoption and use of new 


Recommendations 


First, to encourage innovation it is important to clarify how the 
effectiveness of new approaches will be evaluated by examiners, 
including how technology can provide improved investigative value 


to law enforcement. 


To achieve this, public and private sector stakeholders need to 
work together to define investigative value and agree measures 
and parameters for evaluating effectiveness against it. This would 


thei 


evaluation of program 


the adoption of new te 
patterns of suspicious 


ikely require a move away from indicators such 
SARs filed’ and towards, for example, an increasingly qualitative 

analysis of reports made, their usefulness to law enforcement and 
r alignment with national priorities. Agreeing on a standard of 


effectiveness through 


help precipitate clear guidance for Fls and wou 
chnologies more able to 


behavior 


more effectively. 


as ‘the number of 


international fora would 
d help accelerate 
identify complex 


Finally, supervisory authorities may need to invest in the expertise 
and training of examiners to faci 


itate better understanding and 


appreciation of new technology-driven approaches so that they can 
be assessed more effectively. 


Second, emerging technologies can help an FI to aggregate and 
analyze significantly more data than in the past by using, for 
example, machine learning, Al, analytics tools, and data science. 
become increasingly important as traditional 
tion), is supplemented with new data 
generated through, for example, the increased use of online banking, 
ched through aggregation with contextual 
able through proprietary open-source data 

g technology and increasing data volumes, 


These capabilities wi 
data (e.g., KYC informa 


all of which can be enri 
information made avai 
providers. By leveragin 
Fls will be better equip 


ped to focus analytical 


national priority and wi 


more quickly. 


efforts on areas of 


ll be able to identify new and emerging risks 


The public and private sectors should work together to establish 
a framework to allow for greater agility around adjustments to 
transaction monitoring rules and models. Facilitating the ability of Fis 


toma 
and 
with 


national priorities 
innovative approa 


Third, assessing the ro 


e changes to their risk coverage mode 


is critical to realizing th 


e of new technologies 


s to align to new risks 
e benefits associated 


ches and emerging technologies. 


in tackling financial 


crime, consideration should be given toward striking the right balance 


between rules governing data privacy and pro 


tection (DPP), and rules 


techno 


ogies and it is important that stakeholders continue to work 


governing AML/C 


FT. The two frameworks are often characterized 


collaboratively to provide clarity on key issues, including for example 
how the effectiveness of new technologies will be tested and 
evaluated at the supervisory level. 


as being in tension with 


each other; DPP rules 


broadly restricting 


the sharing of data, and the AML/CFT rules demanding it (at least in 
relation to suspicion). 


25 


The effectiveness of financial crime risk management reform and next steps on a global basis 


As noted elsewhere in this paper, information sharing is a critical they should be successfully applied across a nation’s financial crime 
enabler in enhancing the effectiveness of all aspects of the fight risk management architecture and how they should be measured 
against financial crime. This applies absolutely in the context of regarding actual outcomes that disrupt the activities of money 
technology, where the development of potentially transformative aunders, fraudsters and other malign actors. Achieving uniformity 
capabilities and outpacing reforms to the legislative framework. As when it comes to measuring success for financial crime risk 
such, itis vital that stakeholders continue to focus their efforts toward management also stems from lack of uniformity at the jurisdictional 
defining and agreeing on the correct balance between DPP and AML/ evel in capturing outcomes of FATF Mutual Evaluations in national 
CFT rules at both the domestic and international levels to accelerate risk assessments. 
and enable appropriate technological innovation. 

The fundamentals of AML/CFT and the weaknesses of wider financial 
Privacy enhancing technologies (PETs) - specialist cryptographical crime prevention strategies across certain jurisdictions is the 
capabilities, which allow computations to take place on underlying result of having less resources to apply to the rudimentary tenets 
data, without the data owner necessarily divulging that underlying of a system which delivers on risk management and compliance 
data - can be part of the solution. However, consideration of the objectives. The issue of fundamentals also arises in the broader 
use of PETs should be balanced with discussion on the need for context of understanding between the public and private sectors on 
regulatory/legal clarity on information sharing and the use of data to the modes of financial intermediation and how best to protect the 
support technological innovation as the ultimate goal. provision of financial services from criminal incursion. 
Fourth, stakeholders should focus on increasing understanding Progress continues to be made, however, in these areas, as noted 
in jurisdictions around the world on how new technologies can in Part 1 of this paper. For instance, the FATF continues its work in 
contribute to better baseline risk and compliance functions. This measuring effectiveness as part of its Mutual Evaluation Processes, 
would likely include additional efforts by technologists to educate a key component assessing the use and impact of FATF standards 
regulators, policymakers, and Fls themselves, and would help ensure and identifying deficiencies in such areas as policy coordination, 
that the potential value of new technologies was fully understood, the application of preventative measures, and approaches to 
helping to accelerate policy reform to enable their use. The FATF investigation and prosecutions. Through the broader G-20 work on 
should form part of a core component in technical assistance nhancing cross-border payments, the challenges caused by the 
offered to the public and private sectors on increasing AML/CFT ivergent implementation of AML/CFT requirements is also being 


he EU is also currently in the process of revising its standards for 
4. International cooperation and L/CFT regulation and supervision with a focus on consistency 
capacity building in application of rules across the bloc, a push toward more central 
supervision, and greater cooperation among national authorities 
and law enforcement. As has been noted, the US is driving toward 
reforms embedded in the US AMLA which aims to move its system 
toward a regime focused more on effective outcomes and less on 
technical or “check the box” compliance. 


e 
d 
programmatic effectiveness through the use of technology. examined. 
T 
A 


Background 


nconsistencies in the application of AML/CFT measures and broader 
anti-financial crime matters across jurisdictions continues to impede 
broader efforts to prevent and mitigate illicit financial flows and 
impact reforms across all areas referenced in this paper. Rules, along 
with penalties for non-compliance, that are generally congruous 
domestically and internationally would make it harder for criminals 
to engage in regulatory arbitrage, exploiting gaps in financial crime 
protections in one jurisdiction, and would thus eliminate one of 

the incentives criminals have to channel their operations through 
jurisdictions they know are less resilient than others. 


evertheless, there is still a lack of uniformity in progress across 
the globe around these issues and further work should focus 
on increased international cooperation and coordination, as 
well as on building capacity for countries and institutions to get 
the fundamental building blocks of an effective financial crime 
risk management framework right. As such, as domestic and 
international reforms move forward and build on the work currently 
underway a few key issues should be considered. 


ssues likewise remain with regard to the effectiveness of national 
and regional financial crime risk management regimes when set 
out against key goals that an effective AML/CFT system should 
achieve.® It is often the case that countries may misinterpret both 
the letter and the spirit of international standards, distorting how 


Recommendations 
First, a continued focus on highly effective implementation of 


international standards is critical. In addition to the efforts of 
the FATF on promoting effectiveness in implementation of their 


26 


standards, work should progress on how to address 
to that process. For instance, further risk-based global assessments 
by the FATF in specific areas should be established, such as the 

examination by the FATF of all countries at the same 


iSSUeS aS 
data. This 
between 
reforms. 


Developing common stand 
should 
guidance 
contribute to a better and 
overal 
FATF guidan 
in FATF member jurisdictio 
currently underway at the 
address th 


More broad 
effective an 
be implem 
the Wolfsbe 
government agencies shou 
CTF programs based on wh 
and regulati 
governmen 


t agencies in de 


d asses 


y, countries should focus on the basics 0 
ti-financial crime system mean 
ented in ways that achieves key 
rg Group has stated that supervisors and/or relevant 


sthee 


ether they: 1. comply with AML/CTF 
ons; 2. provide highly useful in 
fined priority areas; and 3. establish a 


reasonable and risk-based set of controls 


Fl being used to facilitate illi 


Such an approach, if consid 
implemented properly at t 
achieving clarity and consi 
will add to the value the p 
and other authori 
mitigation and preventi 


Ss 


on 
Based on this common 


should be more carefu 
disruption, and ac 
we are achieving the ul 
of financial crime. 


Second, th 


cit activ 


ered co 


tency in 


rivate sec 
ties tasked with delivering on 
measures. 


ity. 
lective 


regula 


tor Can 


understanding on wha 
even beyond the FATF metrics, shou 
consideration given to 
tual arrests and prosecutions to assess whether 
timate goals i 


ere needs to be greater bilatera 


d also be co 


n the miti 


The effectiveness of financial crime risk management reform and next steps on a global basis 


improvements 


time on such 


information exchange and access to beneficial ownership 
dynamic approach could potentially remove the lag time 
utual Evaluations, which can take years an 


dstymie 


ards regarding the process that countries 
follow when implementing FATF recommendations and 

in order to engage stakeholders appropriately so they can 
more coherent regulatory environment 

. Establishing a better process to make implementation of 

ce clearer, more effective, measurable, and consistent 
ns may also help. The strategic review 
FATF should be used as the driver to 

ese issues going forward. 


f what an 
s and how that system can 
objectives. For example, 


L/ 
aws 


ffectiveness of Fis AM 


formation to relevant 


to mitigate the risks of an 


y across jurisdictions and 


e supervisory level, will greatly assist in 


tory expectations. This 
bring to law enforcement 
financial crime risk 


t effectiveness means, 
nsidered. There 
success in reporting, 


gation and prevention 


| and multilateral 


cooperation globally, focused on delivering specific areas of consistent 
reform across jurisdictions in an expedited fashion. As such, alongside 


efforts at g 


obal fora like the FATF, FSB, CPMI a 


nd BCBS, countries 


themselves should enhance cross-border dialogue on areas of 


mutual concern. They should also examine ways to deliver broadly 
similar outcomes through methods such as equivalence or mutual 
recognition determinations, memoranda of understanding (MOUs), 
or enhanced mechanisms of international regulatory and supervisory 


cooperation. 


For example, on-going dialogues across m 


ultiple countries currently 


exist in the area of financial services. These should be leveraged 
to focus on specific issues where areas of cooperation could 


be maximized, such as methods of exchan 


information and coordinating inte 
registries. 


ch cooperation is already ta 


and Singapore recently signed an 


cybersecurity, which includes data shari 
replicated across financial crime data an 
from diffe 
supervisory regimes are recognized, where comity 
should be considered a priority of intern 
reforms can 
the use of supervisory colleges that bri 


ough the limitations arising 


address t which 
Similarly, 
regulatory authorities across juris 
AML, CFT and other financial crim 


focus on 


the speeda 


a better understandi 
existing stru 
duplication i 
Enhanced coordination on AML/C 
issue. In nati 
that play a si 
This can lead to inefficienci 
th 


es and 


should encompass all face 
through regulatory, supervisory, a 
mechanisms—Including th 
measures where needed - and th 
sector. 


For instance, in the EU, considera 
AML authority across the bloc wh 


may not be appropriate in all case 
implementation, but certain princ 


ere are different approaches how fi 
and enacted across the globe, at a minimu 


rough collabora 


tion is being given to acen 
ich aims to establish a single 
integrated system of AML/CFT supervision. Such centralizati 


roperability of beneficial o 


MOU 


d across other 
rent legal, regu 
can 
ational 
be undertaken. 
together 
fically in the 
dbeen 


dictions speci 
e matters cou 


finan 


here are often myriad 


m, greater coordi 


ts of the national or regional approach 
aw enforcement coopera 
tion on prudential 


nd 


rough cooperation with th 


addressing financia 
ineffective outcomes. Though 
nancial crime policy is overseen 


ging financial crime 


wnership 


ing place in other policy areas. The US 
to expand cooperation 
ng.’ Such a process could be 
jurisdic 
atory, or 

be advanced it 
ogue and can help 


on 


tions. 


areas of 


hanced to 

areas where MOUs could be developed on key methods of 
addressing risk in a similar fashion. These dialogues can 
ng of jurisdictional approaches to 
that could be leveraged more broadly, as long as they m 
ctures and do not add additional layers of complexity or 
nsupervision or compliance. 


also provide 


cial crime 


aximize 


FT is also not just an international 
onal or regional settings 
gnificant role in government in 


actors 


crime. 


nation 


tion 


e€ private 


tral 


on 


s and requires careful des 


broadly in this area. Specifically, th 


ign and 


iples should be considered more 
ought should be given to how 


27 


The effectiveness of financial crime risk management reform and next steps on a global basis 


countries and region 


al authorities can encompass greater consistency 


in hierarchical powers for oversight/enforcement and greater 


coordination of regu 
coordination across 


Third, ensuring the 
are right is a global priority.2° Much has been discussed in recent 


years about building capacity at Fls through training and technical 


assistance 


this has formed part of the work at the 


Coordinati 
decline in 


However, t 


one aspec 
across juri 


Additiona 


that type of fina 


other 


funda 


in response to 


on Group in res 


atory/supervisory bodies and FIUs, along w 


ith 
countries and with the private sector. 


mentals of financial crime risk management 


the issues around “de-risking” and, indeed, 
FSB's Correspondent Banking 
ponse to trends that contributed to a 


and techn 
as defined 
stakeho 
education 


by the 


programs, train 


ncial activity. 


he issues are broader than simply working to address 
t of financial intermediati 
sdictions more generally 
uniform outcomes in cross-border 
work should thus be considered on education, training, 
ical assistance across all measurements of effectiveness 
FATF, °° including 
ders. Standards implemen 


on. Addressing inadequacies 
could assist in achieving further 
compliance and risk management. 


for public and private sector 
tation can be improved through 
ing and supporting the FATF. 


Technical assistance to help governments, regulators, and Fls 
improve their AML/CFT legal and regulatory frameworks and related 
ices, is an important step to reducing financial 

B is placed to take this issue up more broadly, in 


supervisory pract 


crime risk. 


The FS 


coordinat 
to advanc 


This assis 
taskforce 
programs 


their 
meas 
princi 


programs globally, wh 
ficities; and 3. coordin 
bodies (including the 


speci 


Bank 


required, and enhanci 
ples. Proper pub 


ey 


princi 
assis 


Lastly, capacity bui 
of expertise between t 
mechanisms for co 
between Fis and law en 
Capacity building shou 


tance is also a 


ion with 


tance could 
that could 1 
initiated by 
usefulness in 


ples and practic 


and the private 


e many of th 


achievin 
urements of effective 
es that can be applied to technical assistance 


take 
. take 
the p 


ile ta 


ld 


ic fu 


the form of a cen 


factor to consider. 


ing cana 
he public and private sectors. PPPs and other 
laboration 
forcement or regulatory/supervisory bodies. 
d be encouraged, especially in jurisdictions 


the FATF and both national and regional authorities, 
e key objectives outlin 


ed here. 


tralized FSB-led 

a stock of current technical assistance 
ublic and private sectors and evaluate 

g objectives aligned with the FATF 

ness; 2. based on that exercise, establish 


ing account of national and regional 
ate amongst governments, international 


nternational Monetary Fund and the World 
sector on establishi 
ng programs where needed, in line with the final 


ng programs where they are 


nding to provide countries with technical 


so be assisted via the cross-pollination 


have worked to enable secondments 


where it is not a regular facet of interaction between public authorities 


and obliged entities. A 


tthesa 


me time, it will be important to 


safeguard sensitive information and to clearly demarcate roles. 


The effectiveness of financial crime risk management reform and next steps on a global basis 


Contacts 


IIF contacts 


Tim Adams Andres Portilla Matthew Ekberg 
President and Chief Executive Officer Managing Director, Senior Policy Advisor, 
+1 202 857 3600 Regulatory Affairs Regulatory Affairs 
+1 202 857 3645 +1 202 857-3622 
aportilla@iif.com mekberg@iif.com 


Deloitte contacts 


Michael Shepard Clint Stinger Chris Bostock 

Global Financial Crime Leader Principal, US AML and Sanctions Leader, Director, Leader of the Deloitte 

Deloitte Global Deloitte Transactions and Business Analytics LLP | Forum for Tackling Illicit Finance 

mshepard@deloitte.com Deloitte United States Deloitte United Kingdom 
cstinger@deloitte.com cbostock@deloitte.co.uk 


Contributors 


j< 


Matt Lappas Yamicha Stephenson 

anager Manager 
Deloitte Risk & Financial Advisory Deloitte Transactions and Business Analytics LLP 
mlappas@deloitte.com ystephenson@deloitte.com 


29 


The effectiveness of financial crime risk management reform and next steps on a global basis 


Endnotes 


30 


Basel Committee on Banking Supervision (September 2012) ‘Core Principles 
or Effective Banking Supervision’ pp. 9 - 14 which refer to the importance of 
inancial integrity to financial stability. 


For further information on these issues, please see: IIF/Deloitte, The Global 
Framework for Fighting Financial Crime: Enhancing Effectiveness and 
mproving Outcomes, October 2019: https://www.iif.com/Publications/ 
D/3606/The-Global-Framework-for-Fighting-Financial-Crime-Enhancing- 
Effectiveness-Improving-Outcomes 


For further information on the impact of the COVID-19 crisis on financial 

crime, please see: IIF, Staff Paper: Financial crime risk management and 

he COVID-19 Pandemic: Issues for closer international cooperation and 
coordination, April 2020: https://www.iif.com/Publications/ID/3867/IIF-Staff- 
Paper-Financial-Crime-Risk-Management-and-the-COVID-19-Pandemic and 
FATF, Statement by the FATF President addressing issues concerning COVID-19 
and measures to combat illicit financing, April 1, 2020 and FATF, COVID-19- 
related Money Laundering and Terrorist Financing Risks and Policy Responses, 
May 4, 2020 


FATF, The FATF Recommendations, Updated June 2021 


FINCEN, GLOBAL WORKSHOP FOR FINANCIAL INVESTIGATORS ON 
DETECTION, INVESTIGATION, SEIZURE AND CONFISCATION OF 
CRYPTOCURRENCIES, Updated January 26, 2018 


FATF, Objectives for the FATF during the German Presidency (2020-2022), June 
2020. 


CPMI, Enhancing cross-border payments: building blocks of a global roadmap, 


July 2020. 


BCBS, Sound management of risks related to money laundering and financing 
of terrorism: revisions to supervisory cooperation, July 2020 and IIF, Re: 
ntroduction of guidelines on interaction and cooperation between prudential 
and AML/CFT supervision, February 2020: https://www.iif.com/Publications/ 
D/3752/IIF-Letter-on-BCBS-AMLCFT-and-Prudential-Supervision- 
Consultation. 


FINCEN, FinCEN Seeks Comments on Enhancing the Effectiveness of Anti- 
oney Laundering Programs, September 16, 2020 


European Commission, COMMUNICATION FROM THE COMMISSION on 
an Action Plan for a comprehensive Union policy on preventing money 
aundering and terrorist financing, 7 May 2020. 


European Commission, Beating financial crime: Commission overhauls anti- 
money laundering and countering the financing of terrorism rules, July 2020. 


. "Payment Services (Amendment) Bill" - Second Reading Speech by Mr Ong 


Ye Kung, Minister for Transport, on behalf of Mr Tharman Shanmugaratnam, 
Senior Minister and Minister-in-charge of the Monetary Authority of Singapore 
(4 January 2021), Available at https://www.mas.gov.sg/news/speeches/2021/ 
payment-services-amendment-bill 


. Consultation Paper on Proposed AML Notices for Cross-Border Business 


Arrangements of Capital Markets Intermediaries under Proposed Exemption 

Frameworks (12 May 2021), Available at https://www.mas.gov.sg/publications/ 
consultations/2021/cp-on-proposed-aml-notices-for-crossborder-biz-of-cmis- 
under-proposed-exemption-fwks 


. MAS Consultation Paper on the FI-FI Information Sharing Platform 


for AML/CFT (1 October 2021) https://www.mas.gov.sg/publications/ 
consultations/2021/fi-fi-information-sharing-platform-for-amlcft 


20. 


21. 


22: 


23; 


24, 


25. 


26. 


27. 


28. 


29. 


30. 


31, 


32. 


33. 


. The adequacy and efficacy of Australia’s anti-money laundering and 


counter-terrorism financing (AML/CTF) regime, 2021: https://www.aph.gov. 
au/Parliamentary_Business/Committees/Senate/Legal_and_Constitutional_ 
Affairs/AUSTRAC 


. Afreximbank: https://www.mansaafrica.com/wps/portal/AFRIXEM_Portal/ 


AboutMANSA/lut/p/z0/04_Sj9CPykssyOxPLMnMZzOvMAfIjo8zifSx9DQyN_ 
Q38DMIM3QwczQNCDYMCDIOMPI31g90K9AUyHRUBBATYRQ!!/ 


Reference and covered in more depth on Page 14 of this paper. 


Please see: https://www.nvb.nl/english/transaction-monitoring-netherlands- 
a-unique-step-in-the-fight-against-money-laundering-and-the-financing-of- 
errorism/ 


Please see: https://invidem.com/ 


FINCEN, FinCEN Director Emphasizes Importance of Information Sharing 
Among Financial Institutions, December 10, 2010 


n November 2017, the FATF adopted revisions concerning the interpretative 
note to Recommendation 18 clarifying how assessors and advisors should 
determine the extent of sharing of information at group-wide level, including 
with branches and subsidiaries, and whether or not sufficient safeguards are 
in place to ensure confidentiality and prevent tipping-off. 


This includes countries like UK and Singapore. 


FATF, Revisions to Recommendation 24 - White Paper for Public Consultation, 
une 2021 


The Pandora Papers are 11.9 million leaked documents concerning offshore 
ax issues and other matters published by International Consortium of 
nvestigative Journalists (IC) beginning on 3 October 2021. 


Based on this, tiered access for legitimate interest by other stakeholders 
beyond competent authorities and financial institutions could be considered. 


IF, RE: Revisions to Recommendation 24 - White Paper for Public Consultation, 
August 2021 


Based on this, tiered access for legitimate interest by other stakeholders 
beyond competent authorities and financial institutions could be considered. 


IF, RE: Revisions to Recommendation 24 - White Paper for Public Consultation, 
August 2021 Deloitte, Deloitte connects 5 Dutch banks to make an impact 
with Transaction Monitoring Netherlands (TMNL), 2020 


FATF, STOCKTAKE ON DATA POOLING, COLLABORATIVE ANALYTICS AND DATA 
PROTECTION, 2021, Page 11 


Anti Money Laundering and Counter Terrorism Financing and Other 
Legislation Amendment Act 2020 


USA Patriot Act, Section 314(b) 


Federal Register: Notice of Proposals To Engage in or To Acquire Companies 
Engaged in Permissible Nonbanking Activities , 314(b) Information Sharing - a 
Valuable, but Underutilized Tool - RegTech Consulting, LLC 


eynote Speech by Ms Loo Siew Yee, Assistant Managing Director (Policy, 
Payments & Financial Crime), Monetary Authority of Singapore, at the 
Wealth Management Institute Industry Forum on the Future of Anti-Money 
Laundering with Artificial Intelligence and Machine Learning on 5 August 2021 
(mas.gov.sg) 


34. 


35; 


36. 


37. 


38. 


39. 


45. 


46. 


47. 


48. 


49. 


50. 


The effectiveness of financial crime risk management reform and next steps on a global basis 


Solutions that are adopted in Singapore to such policy and operational 
considerations, including data standards, systems connectivity, cross border 
sharing, safeguards on data protection and appropriate use, are elaborated 
in MAS public consultation paper at: https://www.mas.gov.sg/publications/ 
consultations/2021/fi-fi-information-sharing-platform-for-amicft 


For example, data driven risk assessment as a yearly exercise could be further 
enhanced by concrete modelling of data already available to local regulators 
in terms of risk exposure. Such data sets can be made available to regulated 
entities to enable their respective risk assessments. 


Please see: FCA, Regulatory Sandbox 
For further information: Economic Crime Plan, 2019 to 2022 Para 5.8 
FATF, Outcomes FATF Plenary, 21-23 February 2018. 


For Recommendation 2, analysis of the FATF Mutual Evaluation Reports (MER) 
since adoption of the outlined changes reflect action in line with the scope of 
supervisory cooperation envisioned - with thirty-six jurisdictions assessed 
under the applicable criteria having a level of compliance in place. However, 
such an evaluation of compliance does not always fully reflect whether the 
Recommendation 2 changes have been effective in what we believe should be 
heir ultimate goal - de-conflicting laws and regulations in relation to AML/CFT 
and data privacy. 


. FATF, Stocktake on Data Pooling, Collaborative Analytics and Data Protection, 
June 2021, Para67 IBID 


BID 
BID, Para 3. 


BID, Para 61 


. For example, the right to privacy is a universal human right in accordance with 


he Universal Declaration of Human Rights and International Covenant on Civil 
and Political Rights and the implications of this are also reflected in national 
rulebooks. 


For example, the CMPI has acknowledged that if banks in a correspondent 
banking relationship cannot provide additional information on customers and 
specific transactions due to legal and regulatory restrictions on information 
exchange, correspondent banks may have no alternative but to block or 
reject certain transactions. This may in some cases lead to the termination 

of some banking relationships and contribute to financial exclusion: CPMI, 
Correspondent Banking, July 2016. 


FSI, Closing the loop: AML/CFT supervision of correspondent banking, 
September 2020. 


AS is providing legislative safeguards to govern necessary, relevant, and 
proportionate sharing, appropriate protection and use of information shared 
and measures to address unintended consequences on customers including 
potential de-risking. 


f an Flis a global institution with headquarters in another country that has its 
own set of national priorities, the local branches of the Fl should apply to local 
accounts the Priorities set by the local country where the branch is based. 
Local examiners will examine the branches based on the local government 
Priorities. 


Financial Action Task Force (FATF), “Money laundering and terrorist financing 
risks,” accessed August 17, 2021 


FATF, Guidance on Risk-Based Supervision, March 2021 


Sih 


52. 


33; 


54. 


5D; 


56. 


57. 


58. 


59. 


60. 


61. 


62. 


63. 


64. 


65. 


66. 


Financial Crimes Enforcement Network, “FINCEN Issues First National AML/CFT 
Priorities and Accompanying Statements,” 


Such as the Department of the Treasury’s 2020 Illicit Finance Strategy, 

2018 National Risk Assessment and various FinCEN Advisories. Starting 
from priorities instead of risks specific to the Fl, Fls can align their AML/CFT 
programs and resources to identify and mitigate risks of primary concern to 
he local government. 


AS' COSMIC digital platform has prioritized three risk areas, namely misuse 
of shell and front companies, trade-based money laundering and sanctions 
evasion, in its initial phase of implementation. 


The US AML Act emphasized the imperative for AML examiners to be 
retrained. As a result, the requirement for examiner retraining was codified 
in the new legislation. Section 6307 of the AML Act states that each Federal 
examiner reviewing compliance with the Bank Secrecy Act (BSA) shall 

attend appropriate annual training, as determined by the Secretary of the 
Treasury, relating to AML/CFT activities including with respect to: 1) potential 
risk profiles and warning signs that an examiner may encounter during 
examinations; 2) financial crime patterns and trends; 3) the high-level context 
for why AML/CFT programs are necessary for law enforcement agencies 
and other national security agencies and what risks those programs seek 

0 mitigate; and 4) de-risking and the effect of de-risking on the provision of 
financial services. 


FATF, Guidance on Risk-Based Supervision, March 2021. 


Such as the Section 314 authority granted by the USA PATRIOT Act or Section 
7 of the Crime and Courts Act for the UKk’s Joint Money Laundering Intelligence 
Taskforce (JMLIT). 


The Wolfsberg Group, “Statement on Demonstrating Effectiveness” 


European Commission, Methodology for identifying high-risk third countries 
under Directive (EU) 2015/849 and World Bank Group, National Risk 
Assessment Tool Guidance Manual. 


Egmont Group, “2011-2013, The Best Egmont Case Award Publication,” 


Please see: FATF: An effective system to combat money laundering and 
errorist financing: https://www.fatf-gafi.org/publications/mutualevaluations/ 
documents/effectiveness.html 


The Wolfsberg Group, “Statement on Demonstrating Effectiveness” 


Media Release by MAS, "The United States Department of the Treasury and 
Monetary Authority of Singapore Finalise a Memorandum of Understanding 
on Cybersecurity Cooperation” (23 August 2021), Available at https://www. 
mas.gov.sg/news/media-releases/2021/us-treasury-and-mas-finalise-a- 
memorandum-of-understanding-on-cybersecurity-cooperation 


ACFCS, In FinCEN release of AML priorities, Wolfsberg metrics of effectiveness, 
a glimpse of the future of financial crime compliance, July 202 


Please see: FATF: An effective system to combat money laundering and 
terrorist financing: https://www.fatf-gafi.org/publications/mutualevaluations/ 
documents/effectiveness.html 


ACFCS, In FinCEN release of AML priorities, Wolfsberg metrics of effectiveness, 
a glimpse of the future of financial crime compliance, July 202 


Please see: FATF: An effective system to combat money laundering and 
terrorist financing: https://www.fatf-gafi.org/publications/mutualevaluations/ 
documents/effectiveness.html 


31 


\ 


INSTITUTE OF 
INTERNATIONAL 
FINANCE 


oe 


Deloitte. 


This publication has been written in general terms and we recommend that you obtain professional advice before 
acting or refraining from action on any of the contents of this publication. Deloitte LLP accepts no liability for any loss 
occasioned to any person acting or refraining from action as a result of any material in this publication. 


Deloitte LLP is a limited liability partnership registered in England and Wales with registered number OC303675 and its 
registered office at 1 New Street Square, London EC4A 3HQ, United Kingdom. 


Deloitte LLP is the United Kingdom affiliate of Deloitte NWE LLP, a member firm of Deloitte Touche Tohmatsu Limited, 

a UK private company limited by guarantee (“DTTL”). DTTL and each of its member firms are legally separate and 
independent entities. DTTL and Deloitte NWE LLP do not provide services to clients. Please see www.deloitte.com/about 
to learn more about our global network of member firms. 


© 2021 Deloitte LLP. All rights reserved. 


Designed by Core Creastive Services #RITM0862158 


